Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-17538— Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress <= 5.6.9 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Customer PII Modification

Quick assessment

Affected
latepoint Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 预约预订与保留插件 LatePoint 在 5.6.9 及之前版本中存在不安全直接对象引用(IDOR)漏洞。该漏洞源于 函数在将 POST 请求中的客户数据合并到现有 LatePoint 客户记录时,仅以 (用户是否已登录)作为唯一访问控制机制,而未实施任何所有权验证。因此,具有订阅者(Subscriber)级别或更高权限的已认证攻击者可以修改任意 LatePoint 客户个人信息(包括名、姓、电子邮件地址、电话号码和备注)。此外,当 配置设置为 "phone" 时,攻击者还能够覆盖受害者的电子

CVSS 5.4 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-17538

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress <= 5.6.9 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Customer PII Modification
Source: CVE Program / CVE List V5
Vulnerability Description
The LatePoint - Appointment Booking & Reservation plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.6.9. This is due to the process_step_customer() function using is_user_logged_in() as the sole gate before merging POSTed customer data into an existing LatePoint customer, without any ownership checks. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the personal information (first name, last name, email, phone, notes) of arbitrary LatePoint customers, and, when the contact_merge setting is 'phone', to overwrite the victim's email address and take over the account via a password reset.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
latepoint Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress 0 ~ 5.6.9 -

II. Public POCs for CVE-2026-17538

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-17538

请登录查看更多情报信息。

Other References for CVE-2026-17538 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-17538

No comments yet


Leave a comment