CVE-2026-105198: vulnerability in Appointment Booking Plugin
LatePoint < 5.7.3 - Unauthenticated Customer PII Disclosure via IDOR
Published
0Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Track
exploitation probability
—
observed exploitation
nono source reports it
The Appointment Booking Plugin WordPress plugin before 5.7.3 does not verify that the caller owns the order referenced by an order-item identifier before rendering that order's confirmation summary, letting an unauthenticated visitor retrieve any customer's name, contact details and order confirmation code by supplying a sequential order-item id.
Affected products
Unknown · Appointment Booking PluginRelated CVEs — Appointment Booking Plugin
In the same product, most dangerous first.
CVE-2026-15250MEDIUMLatePoint < 5.6.8 - Unauthenticated Booking Object Mass Assignment via Public Booking FunnelEPSS 0.3%CVE-2026-11866MEDIUMLatePoint < 5.6.3 - Multiple Privileged Actions via CSRFEPSS 0.1%CVE-2026-105197—LatePoint < 5.6.5 - Agent+ Arbitrary Order, Customer and Transaction Deletion via IDOREPSS —CVE-2026-105196—LatePoint < 5.6.9 - Agent+ Cross-Agent Data Disclosure and Modification via Abilities APIEPSS —