Insecure Direct Object Reference in Appointment Booking Plugin for WordPress
CVE-2026-18441

4.3MEDIUM

What is CVE-2026-18441?

The Appointment Booking Plugin – LatePoint for WordPress exhibits a significant security flaw due to an Insecure Direct Object Reference. All versions up to and including 5.6.9 are susceptible. This vulnerability arises from insufficient validation of a user-controlled key within the set_customer_object function, allowing unauthenticated attackers to access arbitrary customer records. They can exploit this weakness to enumerate and reveal personally identifiable information, such as first names, last names, email addresses, and phone numbers, especially when customer authentication is disabled and guest checkout is allowed.

Affected Version(s)

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress 0 <= 5.6.9

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sorra
.