CVE-2026-13471
Last modified
CVE-2026-13471 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.3 via the LatePointAbilityDeleteBooking::execute due to missing validation on a user controlled key. This makes it possible for attackers, with LatePoint Agent-level access and above, to read bookings and customer PII (full name, email, phone, and notes) assigned to other LatePoint agents, and delete arbitrary bookings by supplying any booking ID.
Description
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.3 via the LatePointAbilityDeleteBooking::execute due to missing validation on a user controlled key. This makes it possible for attackers, with LatePoint Agent-level access and above, to read bookings and customer PII (full name, email, phone, and notes) assigned to other LatePoint agents, and delete arbitrary bookings by supplying any booking ID. This vulnerability is only exploitable when an administrator has enabled the Abilities API toggles (latepoint_abilities_api, latepoint_abilities_api_delete, and/or latepoint_abilities_api_edit) in the plugin settings.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| latepoint | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress | <= 5.6.3 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-13471?
How severe is CVE-2026-13471?
How do I fix CVE-2026-13471?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-13463IBM Cloud Pak System 2.3.5.0 could allow a local attacker to…7.5
- CVE-2026-13464The Kirki – Freeform Page Builder, Website Builder & Customi…5.3
- CVE-2026-13465Stack-based buffer overflow vulnerability in Altera Trusted …8.1
- CVE-2026-13466Incorrect calculation of buffer size vulnerability in Altera…8.1
- CVE-2026-13467Out-of-bounds write vulnerability in Altera Trusted Firmware…8.1
- CVE-2026-13468The Visualizer – Tables & Charts Manager with Built-in AI Ge…7.5
- CVE-2026-13473IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.…9.8
- CVE-2026-13474Denial of service via malformed HTTP/2 requests in NetScaler…7.5
- CVE-2026-13476IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could all…7.3
- CVE-2026-13477IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 …8.8
- CVE-2026-13478The Zephyr ext2 filesystem driver validates the on-disk bloc…5.5
- CVE-2026-13479The LoRaWAN application-layer clock-synchronization service …4.3
Are you affected by CVE-2026-13471?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
