CVE-2026-105196
LatePoint < 5.6.9 - Agent+ Cross-Agent Data Disclosure and Modification via Abilities API
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Appointment Booking Plugin WordPress plugin before 5.6.9 does not enforce per-record authorization on several of its AI Abilities API actions, allowing an authenticated user holding the LatePoint Agent role, normally restricted to their own records, to read and modify other agents' profile data and read other agents' bookings and associated customer details when the Abilities API feature is enabled.
| Vendor | unknown |
| Product | appointment booking plugin |
| Published | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown appointment booking plugin
Be the first to know when new unknown vulnerabilities affecting unknown appointment booking plugin are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Appointment Booking Plugin
0 < 5.6.9
References
Credits
Artus KG WPScan