CVE-2026-12657
Received Received - Intake

Insecure Direct Object Reference in LatePoint WordPress Plugin

Vulnerability report for CVE-2026-12657, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-02

Last updated on: 2026-07-02

Assigner: Wordfence

Description

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.2 via the 'service_id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to create approved bookings against services explicitly restricted to admins and agents, consuming restricted appointment capacity and triggering unauthorized bookings for admin/agent-only services. The bypass works via both the params[booking][service_id] parameter in steps__load_step and the presets[selected_service] parameter in steps__start, both of which are publicly accessible without authentication.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-02
Last Modified
2026-07-02
Generated
2026-07-02
AI Q&A
2026-07-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
latepoint calendar_booking_plugin to 5.6.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The LatePoint Calendar Booking Plugin for WordPress has a vulnerability called Insecure Direct Object Reference (IDOR) in all versions up to 5.6.2. This occurs because the plugin does not properly validate the 'service_id' parameter, which is controlled by the user.

Due to this missing validation, unauthenticated attackers can create approved bookings for services that are supposed to be restricted only to admins and agents. They can do this by manipulating the 'service_id' parameter in two publicly accessible endpoints without needing to log in.

Impact Analysis

This vulnerability allows attackers to make unauthorized bookings on services that should be limited to admins or agents. As a result, restricted appointment capacity can be consumed by these unauthorized bookings.

This can disrupt normal business operations by filling up appointment slots with illegitimate bookings, potentially causing loss of service availability for legitimate users and administrative confusion.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12657. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart