CVE-2025-3769: Latepoint <= 5.1.92 - Unauthenticated Insecure Direct Object Reference
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.92 via the 'viewbookingsummaryinlightbox' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to retrieve appointment details such as customer names and email addresses.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3769?
CVE-2025-3769 is considered to have a medium severity due to its potential for unauthorized access to booking summaries.
How do I fix CVE-2025-3769?
To fix CVE-2025-3769, update the LatePoint Calendar Booking Plugin for Appointments and Events to version 5.1.93 or later.
What versions are affected by CVE-2025-3769?
CVE-2025-3769 affects all versions of the LatePoint Calendar Booking Plugin for Appointments and Events up to and including 5.1.92.
What kind of vulnerability is CVE-2025-3769?
CVE-2025-3769 is categorized as an Insecure Direct Object Reference vulnerability.
Can CVE-2025-3769 lead to data exposure?
Yes, CVE-2025-3769 can potentially lead to unauthorized access and exposure of sensitive booking information.