→ برگشت به فید آسیبپذیریها
CVE-2026-13471 · latepoint
ارجاع مستقیم ناامن به شیء (IDOR) در افزونه LatePoint
افزونه LatePoint تا نسخه ۵.۶.۳ دارای آسیبپذیری ارجاع مستقیم ناامن به شیء در متد LatePointAbilityDeleteBooking::execute است که به دلیل نبود اعتبارسنجی روی شناسه رزرو کنترلشده توسط کاربر رخ میدهد. مهاجمان با دسترسی سطح Agent و بالاتر میتوانند در صورت فعال بودن تنظیمات Abilities API، رزروها و اطلاعات شخصی مشتریان (نام، ایمیل، تلفن و یادداشتها) سایر نمایندگان را مشاهده کرده و رزروهای دلخواه را حذف کنند که منجر به افشای دادههای حساس و اختلال در سیستم رزرو میشود. با توجه به وجود وصله امنیتی، توصیه میشود فوراً افزونه را به نسخه امن بهروزرسانی کنید.
نسخههای تحت تأثیر
<= 5.6.3
راهنمای اقدام و رفع مشکل (Remediation)
- ۱. پشتیبانگیری: قبل از اعمال هرگونه تغییر، یک بکاپ کامل از پایگاه داده و فایلهای سایت تهیه کنید.
- ۲. بهروزرسانی سریع: افزونه یا هسته latepoint را بلافاصله به آخرین نسخه ارائهشده ارتقا دهید.
- ۳. فایروال و مانیتورینگ: در صورت عدم امکان آپدیت فوری، رولهای امنیتی WAF را فعال کرده و لاگهای وبسرور را پایش نمایید.
مراجع رسمی و مستندات
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.4.2/lib/abilities/abstract-ability.php#L55 ↗
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.4.2/lib/abilities/bookings/abstract-booking-ability.php#L34 ↗
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.4.2/lib/abilities/bookings/delete-booking.php#L47 ↗
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.4.2/lib/abilities/bookings/list-bookings.php#L50 ↗
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.4.2/lib/abilities/class-latepoint-abilities.php#L77 ↗
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.4.2/lib/abilities/customers/list-customers.php#L78 ↗
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.3/lib/abilities/abstract-ability.php#L55 ↗
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.3/lib/abilities/bookings/abstract-booking-ability.php#L34 ↗
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.3/lib/abilities/bookings/delete-booking.php#L47 ↗
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.3/lib/abilities/bookings/list-bookings.php#L50 ↗
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.3/lib/abilities/class-latepoint-abilities.php#L77 ↗
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.3/lib/abilities/customers/list-customers.php#L78 ↗
- https://plugins.trac.wordpress.org/changeset?reponame=&new=3590914%40latepoint&old=3584059%40latepoint ↗
- https://www.wordfence.com/threat-intel/vulnerabilities/id/448df3b0-32a7-4097-a37d-07e253993496?source=cve ↗