{
 "id": "WPSEC-2026-0451",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0451/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0451/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0451/index.md",
 "title": "Appointment Booking Plugin <= 5.7.3 - Unauthenticated Insecure Direct Object Reference to Cart Item Modification via 'active_cart_item[id]'",
 "description": "The LatePoint plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 5.7.0 up to, and including, 5.7.3. This is due to the booking form accepting a client-supplied 'active_cart_item[id]' value for any existing cart item without verifying that it belongs to the visitor's own cart, after which the event registration step saves that item into the visitor's cart. This makes it possible for unauthenticated attackers to take over and overwrite cart items belonging to other visitors, removing them from those visitors' carts.",
 "plugin": {
  "slug": "latepoint",
  "name": "Appointment Booking Plugin",
  "full_name": "Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress",
  "wordpress_org": "https://wordpress.org/plugins/latepoint/",
  "advisories_url": "https://wpsec.com/vuln/plugin/latepoint/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/latepoint"
 },
 "type": "AUTHBYPASS",
 "cwe": [
  "CWE-639"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "5.7.0",
    "from_inclusive": true,
    "to": "5.7.4",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 5.7.0 before 5.7.4"
  ]
 },
 "introduced_in": "5.7.0",
 "fixed_in": "5.7.4",
 "remediation": "Update to 5.7.4 or later.",
 "fix_released": "2026-10-05T10:44:07+00:00",
 "published": "2026-10-06T16:45:40+00:00",
 "updated": "2026-10-06T16:17:12.979662+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0451/",
  "https://plugins.svn.wordpress.org/latepoint/tags/5.7.4/",
  "https://wordpress.org/plugins/latepoint/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/latepoint",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Low",
  "as_of": "2026-10-06"
 }
}