Insecure Direct Object Reference in LatePoint – Calendar Booking Plugin for WordPress
CVE-2026-13471

4.3MEDIUM

What is CVE-2026-13471?

The LatePoint – Calendar Booking Plugin for WordPress contains an Insecure Direct Object Reference vulnerability that arises from inadequate validation on a user-controlled key within the LatePointAbilityDeleteBooking::execute method. This issue permits users with LatePoint Agent-level access or higher to access sensitive booking information and customer personally identifiable information (PII), such as full names, emails, and phone numbers, associated with other agents. Furthermore, these unauthorized users can delete arbitrary bookings by simply providing any booking ID. This vulnerability is activated when the Abilities API toggles are enabled in the plugin settings.

Affected Version(s)

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress 0 <= 5.6.3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

skyv3il
Chirita Catalin-Andrei (CC99IE)
AmonRa
MrProperCTF
.