CVE-2026-105198
Received Received - Intake

Unauthenticated Order Data Exposure in Appointment Booking Plugin

Vulnerability report for CVE-2026-105198, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: WPScan

Description

The Appointment Booking Plugin WordPress plugin before 5.7.3 does not verify that the caller owns the order referenced by an order-item identifier before rendering that order's confirmation summary, letting an unauthenticated visitor retrieve any customer's name, contact details and order confirmation code by supplying a sequential order-item id.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Appointment Booking Plugin 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an Insecure Direct Object Reference (IDOR) flaw in the WordPress plugin LatePoint before version 5.7.3. It allows unauthenticated attackers to access sensitive customer data by exploiting missing authorization checks. By providing a sequential order-item ID, an attacker can retrieve customer names, contact details, and order confirmation codes without proper verification of ownership.

Detection Guidance

To detect this vulnerability, check if your WordPress site uses the LatePoint plugin version prior to 5.7.3. Inspect the plugin files for missing authorization checks in order-item handling. Manually test by attempting to access order confirmation summaries with sequential IDs without authentication.

Impact Analysis

Unauthenticated attackers can steal personally identifiable information (PII) such as customer names, contact details, and order confirmation codes. This could lead to identity theft, fraud, or unauthorized access to customer accounts. Businesses using the vulnerable plugin may face reputational damage and loss of customer trust.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA requirements for protecting personally identifiable information. It exposes customer data without proper safeguards, potentially leading to regulatory fines, legal liabilities, and mandatory breach notifications under these standards.

Mitigation Strategies

Immediately update the LatePoint plugin to version 5.7.3 or later. Remove or disable the plugin if an update is not possible. Monitor for unauthorized access attempts or data leaks. Apply the latest security patches as soon as they are available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105198. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart