Description
The Appointment Booking Plugin WordPress plugin before 5.6.9 does not enforce per-record authorization on several of its AI Abilities API actions, allowing an authenticated user holding the LatePoint Agent role, normally restricted to their own records, to read and modify other agents' profile data and read other agents' bookings and associated customer details when the Abilities API feature is enabled.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized access to agent data and bookings
Action: Apply patch
AI Analysis

Impact

The vulnerability arises because the Appointment Booking Plugin does not verify per-record authorization for several AI Abilities API actions. An authenticated user with the LatePoint Agent role can trigger these actions and read or modify other agents’ profile information, bookings, and associated customer details. This exposure compromises both the confidentiality and integrity of data that should be confined to each agent, potentially allowing an attacker to tamper with booking schedules or alter customer information.

Affected Systems

The affected product is the Appointment Booking Plugin WordPress plugin, versions earlier than 5.6.9. Installations that employ this plugin and enable the Abilities API feature—typically enabled by default—are susceptible. The plugin is listed in the WordPress repository, but no specific vendor information is available.

Risk and Exploitability

Exploitation requires only an authenticated session bearing the LatePoint Agent role; no elevated system privileges or additional network conditions are needed. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited known exploitation at present. Despite the lack of a CVSS score, the fact that the flaw allows unauthorized reading and modification of sensitive booking data indicates a potentially high impact for affected sites.

Generated by OpenCVE AI on October 8, 2026 at 07:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Appointment Booking Plugin to version 5.6.9 or later, which includes the missing authorization checks.
  • If an update cannot be applied immediately, disable the Abilities API feature via the plugin settings to remove the exposed endpoints.
  • Restrict or remove the LatePoint Agent role from users who do not require the ability to edit other agents’ data, ensuring least‑privilege access for all roles.

Generated by OpenCVE AI on October 8, 2026 at 07:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Thu, 08 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Appointment Booking Plugin WordPress plugin before 5.6.9 does not enforce per-record authorization on several of its AI Abilities API actions, allowing an authenticated user holding the LatePoint Agent role, normally restricted to their own records, to read and modify other agents' profile data and read other agents' bookings and associated customer details when the Abilities API feature is enabled.
Title LatePoint < 5.6.9 - Agent+ Cross-Agent Data Disclosure and Modification via Abilities API
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-08T06:00:07.084Z

Reserved: 2026-10-04T11:57:55.630Z

Link: CVE-2026-105196

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T06:16:40.250

Modified: 2026-10-08T06:16:40.250

Link: CVE-2026-105196

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T07:30:13Z

Weaknesses