---
id: CVE-2026-18441
title: >-
  The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for
  WordPress plugin for WordPress is vulnerable to Insecure Direct Object
  Reference in all versions up to, and including, 5.6.9  via the
  set_customer_object due to missi…
summary: >-
  The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for
  WordPress plugin for WordPress is vulnerable to Insecure Direct Object
  Reference in all versions up to, and including, 5.6.9  via the
  set_customer_object due to missi…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-639
vendor: latepoint
product: Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
affected:
  - >-
    appointment_booking_plugin_latepoint_calendar_scheduling_for_wordpress <=
    5.6.9
published: '2026-09-18'
updated: '2026-09-19'
sourceUpdated: '2026-09-19T15:16:58.823'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18441'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.9/latepoint.php#L1006
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.9/lib/controllers/steps_controller.php#L341
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.9/lib/helpers/steps_helper.php#L1184
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.9/lib/models/model.php#L574
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/d80ed885-43f8-43a4-bc61-e9ef92e3207e?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
epss: 0.00243
epssPercentile: 0.15768
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-19T13:19:23.665831Z'
ingestedAt: '2026-09-17T23:31:20.690Z'
---

## Overview

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.9  via the set_customer_object due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to enumerate arbitrary customer records and disclose personally identifiable information -  including first name, last name, email address, and phone number - by iterating the customer[id] parameter. This issue is exploitable only when the site is configured with customer authentication disabled (guest checkout enabled).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
