---
id: CVE-2026-17538
title: >-
  The LatePoint - Appointment Booking & Reservation plugin for WordPress is
  vulnerable to Insecure Direct Object Reference in versions up to, and
  including, 5.6.9
summary: >-
  The LatePoint - Appointment Booking & Reservation plugin for WordPress is
  vulnerable to Insecure Direct Object Reference in versions up to, and
  including, 5.6.9. This is due to the process_step_customer() function using
  is_user_logged_in…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-639
vendor: latepoint
product: Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
affected:
  - >-
    appointment_booking_plugin_latepoint_calendar_scheduling_for_wordpress <=
    5.6.9
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T00:16:35.153'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-17538'
references:
  - url: 'https://plugins.trac.wordpress.org/changeset/3631493/'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/83cdc51f-b5e1-42b9-972a-7e781f97b43e?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-08T00:00:51.989Z'
---

## Overview

The LatePoint - Appointment Booking & Reservation plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.6.9. This is due to the process_step_customer() function using is_user_logged_in() as the sole gate before merging POSTed customer data into an existing LatePoint customer, without any ownership checks. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the personal information (first name, last name, email, phone, notes) of arbitrary LatePoint customers, and, when the contact_merge setting is 'phone', to overwrite the victim's email address and take over the account via a password reset.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
