๐Ÿ” CVE Alert

CVE-2026-105197

UNKNOWN 0.0

LatePoint < 5.6.5 - Agent+ Arbitrary Order, Customer and Transaction Deletion via IDOR

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Appointment Booking Plugin WordPress plugin before 5.6.5 does not verify that a backend staff user is authorized to act on the specific record targeted for deletion, allowing an authenticated user with a record-scoped staff role to irreversibly delete any order, customer, or transaction on the site, including records belonging to other staff and outside their assigned scope.

Vendor unknown
Product appointment booking plugin
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for unknown appointment booking plugin

Be the first to know when new unknown vulnerabilities affecting unknown appointment booking plugin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Appointment Booking Plugin
0 < 5.6.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/05f690b9-8696-4e73-8f42-f6964db3d092/

Credits

Muni Nitish Kumar Yaddala WPScan