CVE-2026-94432: CWE-639 Authorization Bypass Through User-Controlled Key in latepoint Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
The Appointment Booking Plugin – LatePoint for WordPress versions up to 5.7.1 contains an authorization bypass vulnerability due to insecure direct object reference. This flaw allows unauthenticated attackers to enumerate invoices of arbitrary customers and create unauthorized transaction intents linked to other customers' data. The vulnerability arises because the plugin's PayPal transaction creation handler does not verify ownership or require an access key, unlike other payment handlers. This can disrupt legitimate payment flows by invalidating transaction intent keys.
AI Analysis
Technical Summary
CVE-2026-94432 is an authorization bypass vulnerability (CWE-639) in the LatePoint Appointment Booking Plugin for WordPress, affecting versions up to and including 5.7.1. The vulnerability exists in the OsPaypalConnectController::create_order_for_transaction() action, which is exposed as a public unauthenticated AJAX route. This handler loads invoice data by a sequential integer invoice_id without verifying ownership or requiring an access key, unlike sibling Stripe and Razorpay handlers that require a 128-bit UUID access key. Attackers can enumerate invoices belonging to other customers, create unauthorized transaction intent records linked to those customers, and overwrite the intent_key of in-flight transactions. This invalidates the intent_key expected by legitimate payment flows, potentially breaking payment webhook processing.
Potential Impact
The vulnerability allows unauthenticated attackers to enumerate invoices of arbitrary customers and create or overwrite transaction intents linked to other customers' data. This can disrupt payment processing by invalidating transaction intent keys, potentially causing payment webhooks for affected customers to fail. There is no direct confidentiality or availability impact reported, but the integrity of payment transactions is affected.
Mitigation Recommendations
No official patch or fix is currently confirmed for this vulnerability. Users should monitor the vendor's advisory for updates. Until a fix is available, consider restricting access to the vulnerable AJAX endpoint or implementing custom access controls to prevent unauthorized invoice enumeration and transaction intent creation.
CVE-2026-94432: CWE-639 Authorization Bypass Through User-Controlled Key in latepoint Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
Description
The Appointment Booking Plugin – LatePoint for WordPress versions up to 5.7.1 contains an authorization bypass vulnerability due to insecure direct object reference. This flaw allows unauthenticated attackers to enumerate invoices of arbitrary customers and create unauthorized transaction intents linked to other customers' data. The vulnerability arises because the plugin's PayPal transaction creation handler does not verify ownership or require an access key, unlike other payment handlers. This can disrupt legitimate payment flows by invalidating transaction intent keys.
CVSS v3.1
Score 5.3medium
Affected software
latepoint
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-94432 is an authorization bypass vulnerability (CWE-639) in the LatePoint Appointment Booking Plugin for WordPress, affecting versions up to and including 5.7.1. The vulnerability exists in the OsPaypalConnectController::create_order_for_transaction() action, which is exposed as a public unauthenticated AJAX route. This handler loads invoice data by a sequential integer invoice_id without verifying ownership or requiring an access key, unlike sibling Stripe and Razorpay handlers that require a 128-bit UUID access key. Attackers can enumerate invoices belonging to other customers, create unauthorized transaction intent records linked to those customers, and overwrite the intent_key of in-flight transactions. This invalidates the intent_key expected by legitimate payment flows, potentially breaking payment webhook processing.
Potential Impact
The vulnerability allows unauthenticated attackers to enumerate invoices of arbitrary customers and create or overwrite transaction intents linked to other customers' data. This can disrupt payment processing by invalidating transaction intent keys, potentially causing payment webhooks for affected customers to fail. There is no direct confidentiality or availability impact reported, but the integrity of payment transactions is affected.
Mitigation Recommendations
No official patch or fix is currently confirmed for this vulnerability. Users should monitor the vendor's advisory for updates. Until a fix is available, consider restricting access to the vulnerable AJAX endpoint or implementing custom access controls to prevent unauthorized invoice enumeration and transaction intent creation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-09-21T16:06:17.998Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abf6160a43b0b3b898ac6dc
Added to database: 10/02/2026, 07:46:40 UTC
Last enriched: 10/02/2026, 08:02:12 UTC
Last updated: 10/02/2026, 08:32:48 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.