Impact
A staff user authenticated to the Appointment Booking Plugin (LatePoint) can delete any order, customer or transaction record without proper authorization checks. This classic Insecure Direct Object Reference flaw (CWE‑639) enables the irrecoverable loss of critical sales and personal data. The resulting data destruction can erode customer trust, trigger regulatory penalties, and damage the organization’s reputation.
Affected Systems
The vulnerability exists in all versions of the LatePoint Appointment Booking Plugin before 5.6.5 installed on a WordPress site. No additional vendor or product information is available; the impact applies to any WordPress installation running the affected plugin.
Risk and Exploitability
The EPSS score is not published, and the flaw is not listed in the CISA KEV catalog, but the lack of server‑side authorization verification makes exploitation trivial for any staff member possessing a record‑scoped role. The attacker only needs to know the target record’s identifier, typically by traversing the deletion endpoint, and can cause immediate data loss. Given the high potential damage to data integrity and availability, the risk is considered elevated.
OpenCVE Enrichment