Description
The Appointment Booking Plugin WordPress plugin before 5.7.3 does not verify that the caller owns the order referenced by an order-item identifier before rendering that order's confirmation summary, letting an unauthenticated visitor retrieve any customer's name, contact details and order confirmation code by supplying a sequential order-item id.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized Disclosure of Customer PII via IDOR
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in a WordPress plugin that fails to verify ownership before exposing order details. An attacker can request arbitrary order-item identifiers and obtain a customer’s name, contact details, and order confirmation code. This results in a privacy breach for every user whose order data is exposed, allowing the attacker to collect personally identifiable information without authentication.

Affected Systems

Any WordPress site that has the Appointment Booking Plugin installed and running a version earlier than 5.7.3 is affected. The plugin’s vendor is unknown from the available data; therefore, all installations of the plugin before the stated version must be evaluated for risk.

Risk and Exploitability

The listed CVSS score is not provided, but the vulnerability is exploitable by unauthenticated visitors who supply sequential order-item identifiers. Because the plugin does not perform an ownership check, the attack requires only a web request and no privileged access, making it very low‑barrier. The absence of an EPSS score or KEV listing suggests that exploitation has not yet been widely observed, but the inherent privacy impact remains high. The likelihood of exploitation is difficult to quantify, yet any site with this plugin version remains vulnerable until the fix is applied.

Generated by OpenCVE AI on October 8, 2026 at 08:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Appointment Booking Plugin to version 5.7.3 or later.
  • If upgrading is not immediately possible, restrict direct access to order-item URLs by introducing an authentication check or session validation before displaying order confirmations.
  • Monitor web server logs for repeated or enumeration‑style requests to order-item identifiers to detect potential exploitation attempts.

Generated by OpenCVE AI on October 8, 2026 at 08:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Thu, 08 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Appointment Booking Plugin WordPress plugin before 5.7.3 does not verify that the caller owns the order referenced by an order-item identifier before rendering that order's confirmation summary, letting an unauthenticated visitor retrieve any customer's name, contact details and order confirmation code by supplying a sequential order-item id.
Title LatePoint < 5.7.3 - Unauthenticated Customer PII Disclosure via IDOR
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-08T06:00:07.460Z

Reserved: 2026-10-04T11:59:38.456Z

Link: CVE-2026-105198

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T06:16:40.873

Modified: 2026-10-08T06:16:40.873

Link: CVE-2026-105198

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T08:15:03Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key