Impact
The LatePoint Calendar Booking Plugin for WordPress contains an insecure direct object reference vulnerability in the 'view_booking_summary_in_lightbox' function. Missing validation on a user-controlled key lets an unauthenticated user request booking summaries and obtain sensitive data such as customer names and email addresses. This weakness is classified as CWE-639, reflecting an authorization failure that allows data exposure.
Affected Systems
The vulnerability affects all installations of the LatePoint – Calendar Booking Plugin for Appointments and Events up to and including version 5.1.92. No other affected products or versions are specified.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% shows a very low probability of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a remote attacker sending a crafted HTTP request that includes the unvalidated key to the 'view_booking_summary_in_lightbox' endpoint, which can be performed without authentication.
OpenCVE Enrichment
EUVD