{"data":{"id":"9f2f55cd-6bdb-46d1-b0ff-af6c96816a34","title":"CVE-2026-105196: The Appointment Booking Plugin WordPress plugin before 5.6.9 does not enforce per-record authorization on several of…","summary":"The Appointment Booking Plugin WordPress plugin before 5.6.9 does not enforce per-record authorization on several of its AI Abilities API actions. An authenticated user with the LatePoint Agent role, normally limited to their own records, can read and modify other agents' profile data and read other agents' bookings and associated customer details when the Abilities API feature is enabled.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105196","publishedAt":"2026-10-08T06:16:40.250Z","cveId":"CVE-2026-105196","cweIds":["CWE-639"],"cvssScore":"3.3","cvssSeverity":"low","severity":"low","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":[],"affectedVendorsRaw":["LatePoint","AI Abilities API"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"high","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00132,"epssCheckedAt":"2026-10-10T02:55:29.908Z","kevDateAdded":null,"advisoryAliases":["GHSA-6mwr-f68v-xqw9"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-10T03:42:36.450Z","patchAvailable":null,"disclosureDate":"2026-10-08T06:16:40.250Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.8,"researchCategory":null,"atlasIds":null}}