PT-2026-95283 · WordPress · Latepoint

·

CVE-2026-13471

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions LatePoint – Calendar Booking Plugin for Appointments and Events versions prior to 5.6.4
Description An Insecure Direct Object Reference (IDOR) exists in the LatePointAbilityDeleteBooking::execute function due to missing validation on a user-controlled key. Attackers with LatePoint Agent-level access or higher can read bookings and customer personally identifiable information (PII), including full names, emails, phone numbers, and notes assigned to other agents. Additionally, they can delete arbitrary bookings by providing any booking ID. This issue is only exploitable if an administrator has enabled the Abilities API toggles latepoint abilities api, latepoint abilities api delete, and/or latepoint abilities api edit in the plugin settings.
Recommendations Update the plugin to version 5.6.4 or later. Disable the latepoint abilities api, latepoint abilities api delete, and latepoint abilities api edit toggles in the plugin settings as a temporary mitigation.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13471

Affected Products

Latepoint