Executive brief
LatePoint is a WordPress plugin that manages calendar bookings and customer appointments. The plugin fails to properly validate user permissions when accessing booking records, allowing authenticated agents to view bookings and sensitive customer data (names, emails, phone numbers, notes) belonging to other agents, and to delete any booking by guessing its ID. This exposure occurs only when administrators have enabled optional API features in plugin settings.
Technical details
The vulnerability is an Insecure Direct Object Reference (IDOR) in the LatePointAbilityDeleteBooking::execute method, affecting versions up to 5.6.3. The flaw stems from missing validation of user-controlled booking IDs, allowing attackers with LatePoint Agent-level access or higher to enumerate and manipulate arbitrary bookings. An authenticated attacker can read booking details and PII, or delete bookings, by supplying any valid booking ID. Exploitation requires that administrators have enabled the Abilities API toggles (latepoint_abilities_api, latepoint_abilities_api_delete, and/or latepoint_abilities_api_edit) in plugin settings. Patch availability was not indicated in the advisory.
Affected products
- LatePoint LatePoint – Calendar Booking Plugin for Appointments and Events up to and including 5.6.3
Timeline
- 2026-09-18: disclosed