Insecure Direct Object Reference in LatePoint β Calendar Booking Plugin for WordPress
CVE-2026-13471
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 September 2026
What is CVE-2026-13471?
The LatePoint β Calendar Booking Plugin for WordPress contains an Insecure Direct Object Reference vulnerability that arises from inadequate validation on a user-controlled key within the LatePointAbilityDeleteBooking::execute method. This issue permits users with LatePoint Agent-level access or higher to access sensitive booking information and customer personally identifiable information (PII), such as full names, emails, and phone numbers, associated with other agents. Furthermore, these unauthorized users can delete arbitrary bookings by simply providing any booking ID. This vulnerability is activated when the Abilities API toggles are enabled in the plugin settings.
Affected Version(s)
Appointment Booking Plugin β LatePoint | Calendar & Scheduling for WordPress 0 <= 5.6.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved