CVE detail
CVE-2026-12657
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.2 via the 'service_id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to create approved bookings against services explicitly restricted to admins and agents, consuming restricted appointment capacity and triggering unauthorized bookings for admin/agent-only services. The bypass works via both the params[booking][service_id] parameter in steps__load_step and the presets[selected_service] parameter in steps__start, both of which are publicly accessible without authentication.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 26.4 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 13
- within the 30d window
- Peak daily
- 12
- highest bucket
Evidence
Source links by recency
13 source links · newest first
- Wordfence Intelligence Weekly WordPress Vulnerability Report (June 29, 2026 to July 5, 2026)Wordfence
tory Pro Slider Revolution 7.0.0-7.0.16 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57678 Patch Status Patched Published Jun 30, 2026 Affected Software Slider Revolution [revslider] Researcher daroo More Details > SpaLab | Beauty Salon WordPress Survey Maker by AYS Timetics – Appointment Booking Calendar & S
vendorwww.wordfence.comJul 9, 2026, 3:39 PM - https://www.wordfence.com/threat-intel/vulnerabilities/id/09588c2a-1631-4924-8277-d47f096493c5?source=cvewww.wordfence.com
No excerpt available.
Patchwww.wordfence.comJul 2, 2026, 10:16 AM - https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3584059%40latepoint&new=3584059%40latepoint&sfp_email=&sfph_mail=plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 2, 2026, 10:16 AM - https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.2/lib/helpers/steps_helper.php#L1710plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 2, 2026, 10:16 AM - https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.2/lib/helpers/steps_helper.php#L1618plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 2, 2026, 10:16 AM - https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.2/lib/helpers/steps_helper.php#L1202plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 2, 2026, 10:16 AM - https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.2/lib/controllers/steps_controller.php#L341plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 2, 2026, 10:16 AM - https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.2/lib/controllers/steps_controller.php#L244plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 2, 2026, 10:16 AM - https://plugins.trac.wordpress.org/browser/latepoint/tags/5.3.2/lib/helpers/steps_helper.php#L1710plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 2, 2026, 10:16 AM - https://plugins.trac.wordpress.org/browser/latepoint/tags/5.3.2/lib/helpers/steps_helper.php#L1618plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 2, 2026, 10:16 AM - https://plugins.trac.wordpress.org/browser/latepoint/tags/5.3.2/lib/helpers/steps_helper.php#L1202plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 2, 2026, 10:16 AM - https://plugins.trac.wordpress.org/browser/latepoint/tags/5.3.2/lib/controllers/steps_controller.php#L341plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 2, 2026, 10:16 AM - https://plugins.trac.wordpress.org/browser/latepoint/tags/5.3.2/lib/controllers/steps_controller.php#L244plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 2, 2026, 10:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-59240CVSS 6.9 · Medium
The vulnerability involves an Insecure Direct Object Reference (IDOR) in the `DeleteNotificationController::delete()` method at endpoint `GET /notification/delete/{id}`. The flaw…
- CVE-2026-48052CVSS 5.4 · Medium
Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who is a member of any organization can delete or rename tags be…
- CVE-2026-17570CVSS 4.3 · Medium
Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafte…
- CVE-2026-17531CVSS 1.3 · Low
A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/routes/goals.ts of the component Un…
- CVE-2026-59546CVSS 7.4 · High
Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.
- CVE-2026-59539CVSS 7.5 · High
Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.