CVE-2026-18441 | LatePoint Appointment Booking Plugin up to 5.6.9 on WordPress set_customer_object customer[id] authorization
A vulnerability marked as problematic has been reported in LatePoint Appointment Booking Plugin up to 5.6.9 on WordPress. Impacted is the function set_customer_object. Performing a manipulation of the argument customer[id] results in authorization bypass.
This vulnerability was named CVE-2026-18441. The attack may be initiated remotely. There is no available exploit.VulDB Recent EntriesRead More