4.3
CVE-2026-91050
- EPSS 0.21%
- Veröffentlicht 10.10.2026 05:30:55
- Zuletzt bearbeitet 10.10.2026 06:16:43
- Erkennungen
Appointment Booking Plugin <= 5.7.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Unauthorized Booking Creation and Sensitive Information Disclosure via 'params[presets][order_item_id]' Parameter
Appointment Booking Plugin <= 5.7.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Unauthorized Booking Creation and Sensitive Information Disclosure via 'params[presets][order_item_id]' Parameter
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference / Missing Authorization in versions up to, and including, 5.7.2. This is due to the publicly reachable steps__start and steps__load_step routes accepting a params[presets][order_item_id] value that is copied verbatim into the booking object without verifying that the referenced order item belongs to the current customer, is a bundle item, is paid, or has remaining capacity — the is_bundle_scheduling() bundle discriminator is a mere !empty(order_item_id) truthiness check, and the code flow explicitly removes the customer and payment steps when this is truthy (the source even carries a TODO acknowledging the missing validation). This makes it possible for unauthenticated attackers to create approved appointments against other customers' order items and to read those customers' names, email addresses, and order codes returned in the booking confirmation.
Mögliche Gegenmaßnahme
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress: Update to version 5.7.3, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerlatepoint
≫
Produkt
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
Default Statusunaffected
Version <=
5.7.2
Version
0
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
Version
*-5.7.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.105 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
|
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
https://www.wordfence.com/threat-intel/vulnerabilities/id/136f8e94-a09a-48c4-bea9-e8b21d3fd91f?source=cve
https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.11/lib/helpers/steps_helper.php#L1028
https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.11/lib/helpers/steps_helper.php#L1281
https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.11/lib/models/booking_model.php#L842
https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.11/lib/helpers/steps_helper.php#L677
https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.11/lib/helpers/steps_helper.php#L2350
https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.11/lib/controllers/steps_controller.php#L17
https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.11/lib/controllers/steps_controller.php#L341
https://www.wordfence.com/threat-intel/vulnerabilities/id/136f8e94-a09a-48c4-bea9-e8b21d3fd91f