CVE-2026-94432
Received Received - Intake

Insecure Direct Object Reference in Appointment Booking Plugin – LatePoint

Vulnerability report for CVE-2026-94432, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Wordfence

Description

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.7.1 via the OsPaypalConnectController::create_order_for_transaction() action registered as a public (unauthenticated) route through wp_ajax_nopriv_latepoint_route_call. The handler loads an OsInvoiceModel by a sequential integer 'invoice_id' with no access-key/UUID or ownership check (the sibling Stripe and Razorpay handlers require a 128-bit access-key UUID via OsInvoicesHelper::get_invoice_by_key), and then calls OsTransactionIntentHelper::create_or_update_transaction_intent() which persists a transaction intent tied to the target invoice's customer_id, order_id and charge_amount and regenerates its intent_key before the PayPal-configured guard is reached. This makes it possible for unauthenticated attackers to enumerate invoices belonging to arbitrary customers, create unauthorized transaction-intent rows linked to another customer's data, and overwrite the intent_key of any in-flight NEW-status transaction intent β€” invalidating the intent_key that legitimate Stripe/Razorpay flows are waiting on and breaking payment webhooks for those customers.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
latepoint appointment_booking_plugin to 5.7.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Appointment Booking Plugin for WordPress allows unauthenticated attackers to manipulate transaction data. It occurs because the plugin does not properly verify ownership of invoices before processing transactions. Attackers can create unauthorized transaction records linked to other customers' data, overwrite transaction keys, and disrupt payment processing for legitimate users.

Detection Guidance

To detect this vulnerability, check WordPress sites running the Appointment Booking Plugin – LatePoint versions up to 5.7.1. Look for unauthorized transaction-intent rows or invoice enumeration attempts in database logs. Monitor for unusual wp_ajax_nopriv_latepoint_route_call calls or PayPal-related anomalies.

Impact Analysis

If you use this plugin, attackers could interfere with your payment processing by creating fake transactions or blocking legitimate ones. This could lead to failed payments, disrupted services, or unauthorized access to transaction data. The vulnerability allows enumeration of invoices and manipulation of transaction states without authentication.

Compliance Impact

This vulnerability could lead to violations of GDPR or HIPAA by exposing customer invoice data or allowing unauthorized modifications to transaction records. GDPR requires protection of personal data, while HIPAA mandates secure handling of health-related transactions. The lack of access controls and data integrity checks increases compliance risks.

Mitigation Strategies

Update the Appointment Booking Plugin – LatePoint to the latest version, which should address the insecure direct object reference vulnerability in the OsPaypalConnectController::create_order_for_transaction() function. If an update is not available, consider disabling the plugin temporarily until a patch is released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94432. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart