天下漏洞,尽知其名
MEDIUM

CVE-2026-94432 LatePoint 插件不安全直接对象引用漏洞

影响未授权攻击者可枚举并操作他人发票及交易意图数据

AI 研判

WordPress 插件 LatePoint(预约与日程管理)在 5.7.1 及之前版本中存在不安全直接对象引用(IDOR)漏洞。其 PayPal 连接控制器的 create_order_for_transaction() 动作通过 wp_ajax_nopriv_latepoint_route_call 注册为无需认证的公开路由,处理函数直接以顺序整数 invoice_id 加载发票模型,缺少访问密钥或归属校验。

影响范围

LatePoint

LatePoint 插件 5.7.1 及之前版本(依据漏洞描述,具体受影响版本范围以官方公告为准)。

漏洞详情

漏洞类型为不安全直接对象引用(IDOR)。成因是 PayPal 相关处理逻辑仅凭可预测的顺序整数 invoice_id 加载 OsInvoiceModel,而同类的 Stripe、Razorpay 处理逻辑要求 128 位 access-key UUID 校验。攻击者无需认证即可枚举任意客户的发票,创建与目标发票 customer_id、order_id、charge_amount 绑定的交易意图记录,并覆盖处于 NEW 状态交易意图的 intent_key,从而干扰合法的 Stripe/Razorpay 支付流程。

利用条件与风险

利用无需认证,仅需可预测的整数 invoice_id,攻击门槛低;可导致他人发票信息泄露、非法交易意图写入及在途支付流程被破坏,但 CVSS 5.3 表明直接影响以数据完整性与信息泄露为主。

修复建议

建议升级至官方修复版本(暂无公开的具体修复版本号信息);临时缓解可限制对 wp_ajax_nopriv_latepoint_route_call 路由的访问、禁用 PayPal 支付连接功能,或通过 WAF 拦截相关请求。

原始情报

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.7.1 via the OsPaypalConnectController::create_order_for_transaction() action registered as a public (unauthenticated) route through wp_ajax_nopriv_latepoint_route_call. The handler loads an OsInvoiceModel by a sequential integer ‘invoice_id’ with no access-key/UUID or ownership check (the sibling Stripe and Razorpay handlers require a 128-bit access-key UUID via OsInvoicesHelper::get_invoice_by_key), and then calls OsTransactionIntentHelper::create_or_update_transaction_intent() which persists a transaction intent tied to the target invoice’s customer_id, order_id and charge_amount and regenerates its intent_key before the PayPal-configured guard is reached. This makes it possible for unauthenticated attackers to enumerate invoices belonging to arbitrary customers, create unauthorized transaction-intent rows linked to another customer’s data, and overwrite the intent_key of any in-flight NEW-status transaction intent — invalidating the intent_key that legitimate Stripe/Razorpay flows are waiting on and breaking payment webhooks for those customers.