The LatePoint – Calendar Booking Plugin for Appointments...
Moderate severity
Unreviewed
Published
May 14, 2025
to the GitHub Advisory Database
•
Updated May 14, 2025
Description
Published by the National Vulnerability Database
May 14, 2025
Published to the GitHub Advisory Database
May 14, 2025
Last updated
May 14, 2025
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.92 via the 'view_booking_summary_in_lightbox' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to retrieve appointment details such as customer names and email addresses.
References