🔐 CVE Alert

CVE-2026-91050

MEDIUM 4.3

Appointment Booking Plugin <= 5.7.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Unauthorized Booking Creation and Sensitive Information Disclosure via 'params[presets][order_item_id]' Parameter

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference / Missing Authorization in versions up to, and including, 5.7.2. This is due to the publicly reachable steps__start and steps__load_step routes accepting a params[presets][order_item_id] value that is copied verbatim into the booking object without verifying that the referenced order item belongs to the current customer, is a bundle item, is paid, or has remaining capacity — the is_bundle_scheduling() bundle discriminator is a mere !empty(order_item_id) truthiness check, and the code flow explicitly removes the customer and payment steps when this is truthy (the source even carries a TODO acknowledging the missing validation). This makes it possible for unauthenticated attackers to create approved appointments against other customers' order items and to read those customers' names, email addresses, and order codes returned in the booking confirmation.

CWE CWE-639
Vendor latepoint
Product appointment booking plugin – latepoint | calendar & scheduling for wordpress
Published Oct 10, 2026
Stay Ahead of the Next One

Get instant alerts for latepoint appointment booking plugin – latepoint | calendar & scheduling for wordpress

Be the first to know when new medium vulnerabilities affecting latepoint appointment booking plugin – latepoint | calendar & scheduling for wordpress are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

latepoint / Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
0 ≤ 5.7.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/136f8e94-a09a-48c4-bea9-e8b21d3fd91f?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.11/lib/helpers/steps_helper.php#L1028 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.11/lib/helpers/steps_helper.php#L1281 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.11/lib/models/booking_model.php#L842 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.11/lib/helpers/steps_helper.php#L677 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.11/lib/helpers/steps_helper.php#L2350 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.11/lib/controllers/steps_controller.php#L17 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.11/lib/controllers/steps_controller.php#L341

Credits

Supakiad S. (m3ez)