Skip to content
LowVulnerability

CVE-2026-105196: The Appointment Booking Plugin WordPress plugin before 5.6.9 does not enforce per-record authorization on several of…

Identifier
CVE-2026-105196
Published
Record updated
View JSON

Summary

The Appointment Booking Plugin WordPress plugin before 5.6.9 does not enforce per-record authorization on several of its AI Abilities API actions. An authenticated user with the LatePoint Agent role, normally limited to their own records, can read and modify other agents' profile data and read other agents' bookings and associated customer details when the Abilities API feature is enabled.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.