CVE-2026-5234Disclosure

LOWCVSS 5.3 · MEDIUM

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The LatePoint plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.3.2. The vulnerability exists because the OsStripeConnectController::create_payment_intent_for_transaction action is registered as a public action (no authentication required) and loads invoices by sequential integer invoice_id without any access_key or ownership verification. This is in contrast to other invoice-related actions (view_by_key, payment_form, summary_before_payment) in OsInvoicesController which properly require a cryptographic UUID access_key. This makes it possible for unauthenticated attackers to enumerate valid invoice IDs via an error message oracle, create unauthorized transaction intent records in the database containing sensitive financial data (invoice_id, order_id, customer_id, charge_amount), and on sites with Stripe Connect configured, the response also leaks Stripe payment_intent_client_secret tokens, transaction_intent_key values, and payment amounts for any invoice.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-17: 3PoC Mentioned / Linked · 2026-04-17: 1Technical Details · 2026-04-17: 204-17
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-5234 The LatePoint plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.3.2. The vulnerability exists because the O… https://www.cve.org/CVERecord?id=CVE-2026-5234

    Post summary

    The post announces a CVE‑2026‑5234 IDOR flaw in the LatePoint WordPress plugin affecting all releases up to version 5.3.2, with no patch or exploit details provided.

    0000069
    57.2K followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-5234-latepoint-version-5-3-2-medium-vulnerability-proof-of-concept CVE-2026-5234 #WordPress plugin #vulnerability latepoint #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The text announces a proof‑of‑concept for CVE‑2026‑5234 targeting the Latepoint WordPress plugin, but provides no details on exploitation tools, active attacks, patches, or technical vulnerability specifics.

    0000040
    7 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5234 Insecure Direct Object Reference in LatePoint WordPress Pl... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5234 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    A CVE (CVE‑2026‑5234) for an Insecure Direct Object Reference in the LatePoint WordPress plugin is listed with a link to details, but no PoC, exploit, or patch information is provided.

    0000038
    4.0K followersView on X

Explore more