rootpwn

medium · CVSS v3 5.3 · EPSS 0.00266

CVE-2026-94432

The LatePoint Appointment Booking plugin for WordPress is vulnerable to insecure direct object reference. Unauthenticated users can enumerat

Overview

The LatePoint Appointment Booking plugin for WordPress is vulnerable to insecure direct object reference. Unauthenticated users can enumerate invoices and create or modify transaction intents, potentially disrupting payment processing. This flaw can lead to unauthorized charges and webhook failures.

Description

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.7.1 via the OsPaypalConnectController::create_order_for_transaction() action registered as a public (unauthenticated) route through wp_ajax_nopriv_latepoint_route_call. The handler loads an OsInvoiceModel by a sequential integer 'invoice_id' with no access-key/UUID or ownership check (the sibling Stripe and Razorpay handlers require a 128-bit access-key UUID via OsInvoicesHelper::get_invoice_by_key), and then calls OsTransactionIntentHelper::create_or_update_transaction_intent() which persists a transaction intent tied to the target invoice's customer_id, order_id and charge_amount and regenerates its intent_key before the PayPal-configured guard is reached. This makes it possible for unauthenticated attackers to enumerate invoices belonging to arbitrary customers, create unauthorized transaction-intent rows linked to another customer's data, and overwrite the intent_key of any in-flight NEW-status transaction intent — invalidating the intent_key that legitimate Stripe/Razorpay flows are waiting on and breaking payment webhooks for those customers.

Impact

Confidentiality: attackers can view invoice details of other customers. Integrity: they can create or alter transaction intents, potentially causing unauthorized charges. Availability: payment webhooks may fail, disrupting service. Defenders: site owners, payment processors, and affected customers.

Remediation

Update LatePoint to version 5.7.2 or later where the insecure route is removed. If update not possible, disable the wp_ajax_nopriv_latepoint_route_call endpoint or restrict it to authenticated users. Additionally, monitor for abnormal transaction intent creation and review webhook logs.

Risk context

Medium severity (CVSS 5.3) with a low EPSS score of 0.00266 indicates a relatively rare exploitation likelihood, but the impact on payment integrity warrants timely patching.

Affected products

  • LatePoint Appointment Booking
  • WordPress
  • LatePoint Calendar & Scheduling

Scores

Severity
medium
CVSS v2
5
CVSS v3
5.3
CVSS v4
—
EPSS
0.00266

wordpress plugin insecure-direct-object-reference payment unauthenticated invoice-enumeration webhook

← All CVEs