CVE-2026-105197: vulnerability in Appointment Booking Plugin
LatePoint < 5.6.5 - Agent+ Arbitrary Order, Customer and Transaction Deletion via IDOR
Published
0Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Track
exploitation probability
—
observed exploitation
nono source reports it
The Appointment Booking Plugin WordPress plugin before 5.6.5 does not verify that a backend staff user is authorized to act on the specific record targeted for deletion, allowing an authenticated user with a record-scoped staff role to irreversibly delete any order, customer, or transaction on the site, including records belonging to other staff and outside their assigned scope.
Affected products
Unknown · Appointment Booking PluginRelated CVEs — Appointment Booking Plugin
In the same product, most dangerous first.
CVE-2026-15250MEDIUMLatePoint < 5.6.8 - Unauthenticated Booking Object Mass Assignment via Public Booking FunnelEPSS 0.3%CVE-2026-11866MEDIUMLatePoint < 5.6.3 - Multiple Privileged Actions via CSRFEPSS 0.1%CVE-2026-105198—LatePoint < 5.7.3 - Unauthenticated Customer PII Disclosure via IDOREPSS —CVE-2026-105196—LatePoint < 5.6.9 - Agent+ Cross-Agent Data Disclosure and Modification via Abilities APIEPSS —