CVE Watchtower

← Back to CVE List

CVE-2026-18441Wordfence

Description

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.9 via the set_customer_object due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to enumerate arbitrary customer records and disclose personally identifiable information - including first name, last name, email address, and phone number - by iterating the customer[id] parameter. This issue is exploitable only when the site is configured with customer authentication disabled (guest checkout enabled).
Severity Level
MEDIUM (4.3)
Published Date
17/09/2026
Last Modified
17/09/2026
Exploitation Status
????
EPSS Score
0.24% (percentile 15.8%)

CVSS Base Metrics

CVSS v3 (3.x)
MEDIUM 4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Weaknesses (CWE)

CWE-639 - Authorization Bypass Through User-Controlled Key

Affected & Patched Versions

ProductAffected VersionsPatched Version
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPressN/A5.6.10
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.