Impact
LatePoint, the Appointment Booking Plugin for WordPress, has an insecure direct object reference vulnerability that allows unauthenticated attackers to enumerate and expose customer records, exposing personally identifiable information such as first name, last name, email address, and phone number.
Affected Systems
The vulnerability affects all versions of LatePoint up to and including 5.6.9. WordPress sites using these plugin releases with guest checkout enabled (customer authentication disabled) are at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates medium severity, and the EPSS score of less than 1% shows a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by sending requests with a manipulated customer[id] parameter on a public WordPress site that has guest checkout enabled, requiring no authentication.
OpenCVE Enrichment