CVE-2026-105196
Received Received - Intake

Authentication Bypass in Appointment Booking Plugin

Vulnerability report for CVE-2026-105196, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: WPScan

Description

The Appointment Booking Plugin WordPress plugin before 5.6.9 does not enforce per-record authorization on several of its AI Abilities API actions, allowing an authenticated user holding the LatePoint Agent role, normally restricted to their own records, to read and modify other agents' profile data and read other agents' bookings and associated customer details when the Abilities API feature is enabled.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Appointment Booking Plugin 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Direct Object Reference (IDOR) issue in the Appointment Booking Plugin for WordPress. It affects versions prior to 5.6.9. An authenticated user with the LatePoint Agent role, which should only access their own records, can exploit this flaw to read and modify other agents' profile data and access their bookings and customer details when the Abilities API feature is enabled.

Detection Guidance

Check if the LatePoint plugin version is below 5.6.9. Inspect API requests for unauthorized access to agent profiles or bookings. Monitor logs for unusual activity by LatePoint Agent role users.

Impact Analysis

If you are a user of the Appointment Booking Plugin with the LatePoint Agent role, an attacker with the same role could access your sensitive data and that of other agents. This includes reading and modifying profile information and viewing bookings and customer details, leading to potential privacy breaches and unauthorized data exposure.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized access to personal and sensitive data. GDPR requires protecting personal data, while HIPAA mandates safeguarding protected health information. A breach could result in legal penalties and reputational damage.

Mitigation Strategies

Update the LatePoint plugin to version 5.6.9 or later immediately. Disable the Abilities API feature if not required. Review and restrict permissions for LatePoint Agent role users.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105196. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart