PT-2026-7813 · WordPress · Latepoint – Calendar Booking Plugin For Appointments/Events

Chiao-Lin Yu

·

Publicado

2026-02-12

·

Atualizado

2026-02-12

·

CVE-2026-1537

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions LatePoint – Calendar Booking Plugin for Appointments and Events versions prior to 5.2.7
Description The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress has a flaw that allows unauthorized access to data. This is due to a missing capability check within the load step() function. An unauthenticated attacker can view booking information, including customer names, email addresses, phone numbers, appointment times, and service details.
Recommendations Update to version 5.2.7 or later.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-1537

Produtos afetados

Latepoint – Calendar Booking Plugin For Appointments/Events