CVE-2026-105198: fallo de gravedad media en Appointment Booking Plugin
LatePoint < 5.7.3 - Unauthenticated Customer PII Disclosure via IDOR
Publicada el
10Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.3
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
The Appointment Booking Plugin WordPress plugin before 5.7.3 does not verify that the caller owns the order referenced by an order-item identifier before rendering that order's confirmation summary, letting an unauthenticated visitor retrieve any customer's name, contact details and order confirmation code by supplying a sequential order-item id.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Productos afectados
Unknown · Appointment Booking PluginCVEs relacionadas — Appointment Booking Plugin
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-15250MEDIUMLatePoint < 5.6.8 - Unauthenticated Booking Object Mass Assignment via Public Booking FunnelEPSS 0.3%CVE-2026-11866MEDIUMLatePoint < 5.6.3 - Multiple Privileged Actions via CSRFEPSS 0.1%CVE-2026-105197LOWLatePoint < 5.6.5 - Agent+ Arbitrary Order, Customer and Transaction Deletion via IDOREPSS —CVE-2026-105196LOWLatePoint < 5.6.9 - Agent+ Cross-Agent Data Disclosure and Modification via Abilities APIEPSS —