CVE-2026-105196

CVE-2026-105196: vulnerability in Appointment Booking Plugin

LatePoint < 5.6.9 - Agent+ Cross-Agent Data Disclosure and Modification via Abilities API

Published

0Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Track
exploitation probability
—
observed exploitation
nono source reports it
The Appointment Booking Plugin WordPress plugin before 5.6.9 does not enforce per-record authorization on several of its AI Abilities API actions, allowing an authenticated user holding the LatePoint Agent role, normally restricted to their own records, to read and modify other agents' profile data and read other agents' bookings and associated customer details when the Abilities API feature is enabled.