Sceawere
Vulnerability Detail
CVE-2026-91050UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
LatePoint Plugin IDOR Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 2h ago
- Vendor
- latepoint
- Product
- Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
- Attack Type
- CWE-639 Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference / Missing Authorization in versions up to, and including, 5.7.2. This is due to the publicly reachable steps__start and steps__load_step routes accepting a params[presets][order_item_id] value that is copied verbatim into the booking object without verifying that the referenced order item belongs to the current customer, is a bundle item, is paid, or has remaining capacity — the is_bundle_scheduling() bundle discriminator is a mere !empty(order_item_id) truthiness check, and the code flow explicitly removes the customer and payment steps when this is truthy (the source even carries a TODO acknowledging the missing validation). This makes it possible for unauthenticated attackers to create approved appointments against other customers' order items and to read those customers' names, email addresses, and order codes returned in the booking confirmation.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-10T06:16:43.937Z",
"pubdate": "2026-10-10T06:16:43.937Z",
"executiveSummary": "The LatePoint | Calendar & Scheduling for WordPress plugin is susceptible to an Insecure Direct Object Reference (IDOR) and missing authorization vulnerability affecting versions up to and including 5.7.2.\nThe vulnerability originates from inadequate validation within the steps__start and steps__load_step routes, which accept user-supplied input for order_item_id without verifying ownership, payment status, or booking capacity.\nThis flaw allows unauthenticated attackers to manipulate the booking process to associate unauthorized appointments with existing order items belonging to other customers.\nImpacts include unauthorized appointment creation and the unauthorized disclosure of sensitive customer information, specifically names, email addresses, and order codes contained within booking confirmations.\nThe risk is critical as it permits full bypass of booking logic, potentially compromising the integrity of scheduling systems and exposing private user data to third-party observers.",
"technicalDetails": "The vulnerability exists in the LatePoint plugin's booking flow, specifically within the publicly accessible routes 'steps__start' and 'steps__load_step'.\nThe root cause is a failure to implement server-side authorization checks on the 'params[presets][order_item_id]' parameter. When this parameter is supplied, the application backend treats the input as trusted data and copies it directly into the booking object.\nA key component of the failure is the 'is_bundle_scheduling()' function, which acts as a faulty bundle discriminator. It relies solely on a truthiness check ('!empty(order_item_id)') rather than performing a relational check to verify that the specified ID corresponds to an active, valid, and customer-owned transaction.\nThe application code flow explicitly removes essential security validation steps—specifically the customer identification and payment verification steps—whenever the 'order_item_id' is present. Developers included a TODO comment acknowledging this omission, indicating a known lack of validation during the implementation phase.\nAn attacker can exploit this by crafting a malicious request targeting the vulnerable endpoints. By injecting an arbitrary 'order_item_id' known or guessed from the target system, an unauthenticated attacker can bypass the intended authorization logic.\nThe attack flow proceeds as follows: 1) The attacker sends a request to the vulnerable routes containing a target 'order_item_id'. 2) The plugin backend executes the 'is_bundle_scheduling()' check, which evaluates the presence of the ID as a signal to skip standard authentication and payment validation. 3) The backend proceeds to create an appointment associated with the attacker-provided 'order_item_id'. 4) The API returns a confirmation payload that includes the sensitive PII of the legitimate owner of the 'order_item_id', such as full names, contact email addresses, and unique order codes.\nBecause the system fails to verify whether the order item has remaining capacity or satisfies payment requirements, the attacker can successfully force the creation of approved appointments regardless of the current state of the order item."
}