๐Ÿ” CVE Alert

CVE-2026-105198

UNKNOWN 0.0

LatePoint < 5.7.3 - Unauthenticated Customer PII Disclosure via IDOR

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Appointment Booking Plugin WordPress plugin before 5.7.3 does not verify that the caller owns the order referenced by an order-item identifier before rendering that order's confirmation summary, letting an unauthenticated visitor retrieve any customer's name, contact details and order confirmation code by supplying a sequential order-item id.

Vendor unknown
Product appointment booking plugin
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for unknown appointment booking plugin

Be the first to know when new unknown vulnerabilities affecting unknown appointment booking plugin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Appointment Booking Plugin
0 < 5.7.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/736056ca-5825-4cb7-8775-4010efe1f7cd/

Credits

Vลฉ Quang Huy WPScan