Insecure Direct Object Reference in Appointment Booking Plugin for WordPress
CVE-2026-18441
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 September 2026
What is CVE-2026-18441?
The Appointment Booking Plugin β LatePoint for WordPress exhibits a significant security flaw due to an Insecure Direct Object Reference. All versions up to and including 5.6.9 are susceptible. This vulnerability arises from insufficient validation of a user-controlled key within the set_customer_object function, allowing unauthenticated attackers to access arbitrary customer records. They can exploit this weakness to enumerate and reveal personally identifiable information, such as first names, last names, email addresses, and phone numbers, especially when customer authentication is disabled and guest checkout is allowed.
Affected Version(s)
Appointment Booking Plugin β LatePoint | Calendar & Scheduling for WordPress 0 <= 5.6.9