Impact
The vulnerability arises because the Appointment Booking Plugin does not verify per-record authorization for several AI Abilities API actions. An authenticated user with the LatePoint Agent role can trigger these actions and read or modify other agents’ profile information, bookings, and associated customer details. This exposure compromises both the confidentiality and integrity of data that should be confined to each agent, potentially allowing an attacker to tamper with booking schedules or alter customer information.
Affected Systems
The affected product is the Appointment Booking Plugin WordPress plugin, versions earlier than 5.6.9. Installations that employ this plugin and enable the Abilities API feature—typically enabled by default—are susceptible. The plugin is listed in the WordPress repository, but no specific vendor information is available.
Risk and Exploitability
Exploitation requires only an authenticated session bearing the LatePoint Agent role; no elevated system privileges or additional network conditions are needed. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited known exploitation at present. Despite the lack of a CVSS score, the fact that the flaw allows unauthorized reading and modification of sensitive booking data indicates a potentially high impact for affected sites.
OpenCVE Enrichment