Impact
The flaw lies in LatePointAbilityDeleteBooking::execute where a user‑controlled key is passed without validation, allowing an authenticated attacker with Agent‑level or higher access to delete any booking by providing its ID. The same lack of checks lets the attacker read booking and customer personal information—including full name, email, phone, and notes—associated with other agents. This idempotent insecure reference is a classic IDOR vulnerability (CWE‑639).
Affected Systems
The vulnerability affects the LatePoint Calendar Booking Plugin for WordPress, all releases up to and including version 5.6.3. It is present regardless of the site’s WordPress version as long as the plugin is installed and the Abilities API toggles are enabled.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact. EPSS is below 1 % and the flaw is not listed in CISA’s KEV catalog, suggesting a low probability of widespread exploitation. The attack vector requires that the plugin’s Abilities API toggles (latepoint_abilities_api, latepoint_abilities_api_delete, and/or latepoint_abilities_api_edit) have been enabled and that the attacker possesses Agent‑level credentials or higher. Therefore, while the impact includes data exposure and data deletion, the likelihood of exploitation is mitigated by the need for privileged access and specific plugin configuration.
OpenCVE Enrichment