Impact
The vulnerability allows an unauthenticated user to supply a params[presets][order_item_id] value that the plugin copies into a booking object without verifying ownership, payment status, or capacity. This missing authorization check enables the creation of approved appointments for other customers and causes the booking confirmation to expose the customers’ names, email addresses and order codes. The issue is an instance of Insecure Direct Object Reference (CWE-639).
Affected Systems
LatePoint Appointment Booking Plugin for WordPress – versions up to and including 5.7.2 are affected. Any WordPress site running these versions of the plugin is vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and no EPSS score is available, which means there is no publicly known exploitation data. The plugin’s steps__start and steps__load_step routes are publicly reachable via HTTP, so the attack can be launched remotely by any client with network access. Overall, the risk is moderate but significant because it allows unauthorized use of the booking system and leakage of personal data.
OpenCVE Enrichment