---
id: CVE-2026-13471
title: >-
  The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for
  WordPress is vulnerable to Insecure Direct Object Reference in all versions up
  to, and including, 5.6.3 via the LatePointAbilityDeleteBooking::execute due to
  …
summary: >-
  The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for
  WordPress is vulnerable to Insecure Direct Object Reference in all versions up
  to, and including, 5.6.3 via the LatePointAbilityDeleteBooking::execute due to
  …
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-639
vendor: latepoint
product: Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
affected:
  - >-
    appointment_booking_plugin_latepoint_calendar_scheduling_for_wordpress <=
    5.6.3
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T20:17:05.797'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13471'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/latepoint/tags/5.4.2/lib/abilities/abstract-ability.php#L55
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/latepoint/tags/5.4.2/lib/abilities/bookings/abstract-booking-ability.php#L34
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/latepoint/tags/5.4.2/lib/abilities/bookings/delete-booking.php#L47
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/latepoint/tags/5.4.2/lib/abilities/bookings/list-bookings.php#L50
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/latepoint/tags/5.4.2/lib/abilities/class-latepoint-abilities.php#L77
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/latepoint/tags/5.4.2/lib/abilities/customers/list-customers.php#L78
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.3/lib/abilities/abstract-ability.php#L55
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.3/lib/abilities/bookings/abstract-booking-ability.php#L34
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.3/lib/abilities/bookings/delete-booking.php#L47
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.3/lib/abilities/bookings/list-bookings.php#L50
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.3/lib/abilities/class-latepoint-abilities.php#L77
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.3/lib/abilities/customers/list-customers.php#L78
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&new=3590914%40latepoint&old=3584059%40latepoint
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/448df3b0-32a7-4097-a37d-07e253993496?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-18T19:57:24.068567Z'
epss: 0.00331
epssPercentile: 0.23507
ingestedAt: '2026-09-18T08:38:04.099Z'
---

## Overview

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.3 via the LatePointAbilityDeleteBooking::execute due to missing validation on a user controlled key. This makes it possible for attackers, with  LatePoint Agent-level access and above, to read bookings and customer PII (full name, email, phone, and notes) assigned to other LatePoint agents, and delete arbitrary bookings by supplying any booking ID. This vulnerability is only exploitable when an administrator has enabled the Abilities API toggles (latepoint_abilities_api, latepoint_abilities_api_delete, and/or latepoint_abilities_api_edit) in the plugin settings.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
