Description
The Appointment Booking Plugin WordPress plugin before 5.6.5 does not verify that a backend staff user is authorized to act on the specific record targeted for deletion, allowing an authenticated user with a record-scoped staff role to irreversibly delete any order, customer, or transaction on the site, including records belonging to other staff and outside their assigned scope.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Data Destruction via Authenticated IDOR
Action: Immediate Patch
AI Analysis

Impact

A staff user authenticated to the Appointment Booking Plugin (LatePoint) can delete any order, customer or transaction record without proper authorization checks. This classic Insecure Direct Object Reference flaw (CWE‑639) enables the irrecoverable loss of critical sales and personal data. The resulting data destruction can erode customer trust, trigger regulatory penalties, and damage the organization’s reputation.

Affected Systems

The vulnerability exists in all versions of the LatePoint Appointment Booking Plugin before 5.6.5 installed on a WordPress site. No additional vendor or product information is available; the impact applies to any WordPress installation running the affected plugin.

Risk and Exploitability

The EPSS score is not published, and the flaw is not listed in the CISA KEV catalog, but the lack of server‑side authorization verification makes exploitation trivial for any staff member possessing a record‑scoped role. The attacker only needs to know the target record’s identifier, typically by traversing the deletion endpoint, and can cause immediate data loss. Given the high potential damage to data integrity and availability, the risk is considered elevated.

Generated by OpenCVE AI on October 8, 2026 at 07:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the LatePoint Appointment Booking Plugin to version 5.6.5 or later, which removes the IDOR flaw.
  • If an upgrade cannot be performed immediately, deny deletion permissions to all staff roles or remove the deletion capability from the plugin configuration, and isolate the plugin’s administrative interface to a restricted user group.
  • Implement a server‑side check that confirms the authenticated staff user has explicit authorization for the specific order, customer, or transaction record before allowing deletion, and audit deletion requests to detect unauthorized activity.

Generated by OpenCVE AI on October 8, 2026 at 07:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Thu, 08 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Appointment Booking Plugin WordPress plugin before 5.6.5 does not verify that a backend staff user is authorized to act on the specific record targeted for deletion, allowing an authenticated user with a record-scoped staff role to irreversibly delete any order, customer, or transaction on the site, including records belonging to other staff and outside their assigned scope.
Title LatePoint < 5.6.5 - Agent+ Arbitrary Order, Customer and Transaction Deletion via IDOR
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-08T06:00:07.266Z

Reserved: 2026-10-04T11:58:47.115Z

Link: CVE-2026-105197

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T06:16:40.553

Modified: 2026-10-08T06:16:40.553

Link: CVE-2026-105197

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T07:45:17Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-639

    Authorization Bypass Through User-Controlled Key