Junglewise Threat Intelligence

CVE-2026-12657: LatePoint WordPress Plugin IDOR in service_id parameter

CVE-2026-12657 · Severity: medium · CVSS 5.3 · Published 2026-07-02

Technologies: LatePoint. Vendors: LatePoint.

Executive brief

A vulnerability in the LatePoint booking plugin for WordPress allows unauthorized users to schedule appointments for services that should be restricted to administrators or agents. This could lead to the exhaustion of appointment slots and the creation of unauthorized bookings for private or internal-only services. The issue affects all versions of the plugin up to 5.6.2.

Technical details

The LatePoint plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) via the 'service_id' parameter. The vulnerability stems from missing validation on user-controlled keys within the 'steps__load_step' and 'steps__start' functions, specifically via the 'params[booking][service_id]' and 'presets[selected_service]' parameters. An unauthenticated attacker can exploit this to bypass access controls and create approved bookings for services intended only for admins or agents. This can result in unauthorized resource consumption and scheduling of restricted services. The issue is present in all versions up to and including 5.6.2.

Affected products

  • LatePoint LatePoint – Calendar Booking Plugin for Appointments and Events up to, and including, 5.6.2

Timeline

  • 2026-07-02: disclosed: NVD publication date

References

Related threats