WP Security CheckVulnerability data as of October 10, 2026

Vulnerability alerts / October 9, 2026

Vulnerability in Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress — CVE-2026-91050

MediumSeverity
CVSS 4.3
—Estimated exploit probability
EPSS
100,000+ sitesInstalls
5.7.3Fixed in

What to do now

Update Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress to 5.7.3 or later.

Affected versions

  • Everything up to and including 5.7.2

Affected: Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress (plugin, latepoint)

Check: The plugin on wordpress.org / Our record for Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress

What the vulnerability is

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference / Missing Authorization in versions up to, and including, 5.7.2. This is due to the publicly reachable steps__start and steps__load_step routes accepting a params[presets][order_item_id] value that is copied verbatim into the booking object without verifying that the referenced order item belongs to the current customer, is a bundle item, is paid, or has remaining capacity — the is_bundle_scheduling() bundle discriminator is a mere !empty(order_item_id) truthiness check, and the code flow explicitly removes the customer and payment steps when this is truthy (the source even carries a TODO acknowledging the missing validation). This makes it possible for unauthenticated attackers to create approved appointments against other customers' order items and to read those customers' names, email addresses, and order codes returned in the booking confirmation.

This description is reproduced verbatim from the public vulnerability record.

Sources

Part of this record comes from Wordfence Intelligence. Original: https://www.wordfence.com/threat-intel/vulnerabilities/id/136f8e94-a09a-48c4-bea9-e8b21d3fd91f
Copyright 2012-2026 Defiant Inc. / Full license text

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts