CVE-2026-105197
Received Received - Intake

Unauthorized Record Deletion in Appointment Booking Plugin

Vulnerability report for CVE-2026-105197, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: WPScan

Description

The Appointment Booking Plugin WordPress plugin before 5.6.5 does not verify that a backend staff user is authorized to act on the specific record targeted for deletion, allowing an authenticated user with a record-scoped staff role to irreversibly delete any order, customer, or transaction on the site, including records belonging to other staff and outside their assigned scope.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Appointment Booking Plugin 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Direct Object Reference (IDOR) flaw in the WordPress plugin LatePoint before version 5.6.5. It allows authenticated users with a record-scoped staff role to delete any order, customer, or transaction on the site without proper authorization checks. This includes records belonging to other staff or outside their assigned scope, leading to irreversible data loss.

Detection Guidance

To detect this vulnerability, check if your WordPress site uses the Appointment Booking Plugin (or LatePoint) versions prior to 5.6.5. Log in as a staff user with record-scoped permissions and attempt to delete records outside your assigned scope. If deletion succeeds without proper authorization, the vulnerability exists.

Impact Analysis

If exploited, this vulnerability could allow unauthorized users to delete critical data such as orders, customer records, or transactions. This could disrupt business operations, cause data loss, and potentially affect customer trust and financial records.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA by allowing unauthorized deletion of personal or sensitive data. GDPR requires protection of personal data, and HIPAA mandates safeguarding protected health information. Unauthorized deletions may violate these regulations, resulting in legal penalties or fines.

Mitigation Strategies

Immediately update the Appointment Booking Plugin (or LatePoint) to version 5.6.5 or later. If updating is not possible, disable the plugin temporarily until the update is applied. Review all staff user permissions to ensure proper access controls are in place.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105197. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart