CVE-2026-91050
Received Received - Intake

Insecure Direct Object Reference in Appointment Booking Plugin – LatePoint

Vulnerability report for CVE-2026-91050, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Wordfence

Description

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference / Missing Authorization in versions up to, and including, 5.7.2. This is due to the publicly reachable steps__start and steps__load_step routes accepting a params[presets][order_item_id] value that is copied verbatim into the booking object without verifying that the referenced order item belongs to the current customer, is a bundle item, is paid, or has remaining capacity β€” the is_bundle_scheduling() bundle discriminator is a mere !empty(order_item_id) truthiness check, and the code flow explicitly removes the customer and payment steps when this is truthy (the source even carries a TODO acknowledging the missing validation). This makes it possible for unauthenticated attackers to create approved appointments against other customers' order items and to read those customers' names, email addresses, and order codes returned in the booking confirmation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
latepoint Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This WordPress plugin vulnerability allows unauthenticated attackers to create appointments for other customers by exploiting missing authorization checks. The plugin fails to verify if an order item belongs to the current user, allowing attackers to manipulate booking objects and access customer details like names and email addresses.

Impact Analysis

Attackers could create unauthorized appointments for other users, exposing their personal information such as names, email addresses, and order codes. This may lead to privacy breaches and potential misuse of scheduling resources.

Compliance Impact

This vulnerability likely violates GDPR due to unauthorized access to personal data and HIPAA if health-related scheduling data is exposed. It undermines data protection requirements by allowing unauthorized access to sensitive customer information.

Mitigation Strategies

Update the Appointment Booking Plugin – LatePoint to the latest version beyond 5.7.2 immediately to patch the insecure direct object reference vulnerability. Disable public access to the steps__start and steps__load_step routes if not required. Review all existing bookings for unauthorized appointments and remove any suspicious entries.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91050. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart