Description
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference / Missing Authorization in versions up to, and including, 5.7.2. This is due to the publicly reachable steps__start and steps__load_step routes accepting a params[presets][order_item_id] value that is copied verbatim into the booking object without verifying that the referenced order item belongs to the current customer, is a bundle item, is paid, or has remaining capacity — the is_bundle_scheduling() bundle discriminator is a mere !empty(order_item_id) truthiness check, and the code flow explicitly removes the customer and payment steps when this is truthy (the source even carries a TODO acknowledging the missing validation). This makes it possible for unauthenticated attackers to create approved appointments against other customers' order items and to read those customers' names, email addresses, and order codes returned in the booking confirmation.
Published: 2026-10-10
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Booking Creation and Sensitive Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows an unauthenticated user to supply a params[presets][order_item_id] value that the plugin copies into a booking object without verifying ownership, payment status, or capacity. This missing authorization check enables the creation of approved appointments for other customers and causes the booking confirmation to expose the customers’ names, email addresses and order codes. The issue is an instance of Insecure Direct Object Reference (CWE-639).

Affected Systems

LatePoint Appointment Booking Plugin for WordPress – versions up to and including 5.7.2 are affected. Any WordPress site running these versions of the plugin is vulnerable.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and no EPSS score is available, which means there is no publicly known exploitation data. The plugin’s steps__start and steps__load_step routes are publicly reachable via HTTP, so the attack can be launched remotely by any client with network access. Overall, the risk is moderate but significant because it allows unauthorized use of the booking system and leakage of personal data.

Generated by OpenCVE AI on October 10, 2026 at 06:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the LatePoint plugin to the latest release (greater than 5.7.2) where the IDR issue is fixed.
  • If an upgrade is not immediately possible, restrict access to the steps__start and steps__load_step endpoints so that only authenticated users can invoke them, for example by adding HTTP authentication or modifying the plugin’s routing rules.
  • Audit booking logs for suspicious entries and consider removing any appointments that were likely created by an intruder.

Generated by OpenCVE AI on October 10, 2026 at 06:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference / Missing Authorization in versions up to, and including, 5.7.2. This is due to the publicly reachable steps__start and steps__load_step routes accepting a params[presets][order_item_id] value that is copied verbatim into the booking object without verifying that the referenced order item belongs to the current customer, is a bundle item, is paid, or has remaining capacity — the is_bundle_scheduling() bundle discriminator is a mere !empty(order_item_id) truthiness check, and the code flow explicitly removes the customer and payment steps when this is truthy (the source even carries a TODO acknowledging the missing validation). This makes it possible for unauthenticated attackers to create approved appointments against other customers' order items and to read those customers' names, email addresses, and order codes returned in the booking confirmation.
Title Appointment Booking Plugin <= 5.7.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Unauthorized Booking Creation and Sensitive Information Disclosure via 'params[presets][order_item_id]' Parameter
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T05:30:55.254Z

Reserved: 2026-09-14T17:15:11.459Z

Link: CVE-2026-91050

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T06:16:43.937

Modified: 2026-10-10T06:16:43.937

Link: CVE-2026-91050

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T06:45:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key