PatchSiren cyber security CVE debrief
CVE-2026-105197 LatePoint CVE debrief
The Appointment Booking Plugin for WordPress, version prior to 5.6.5, is vulnerable to an insecure direct object reference (IDOR) issue. This allows an authenticated user with a staff role limited to a specific record to delete any order, customer, or transaction on the site, including records outside their assigned scope. The vulnerability was reported by WPScan and documented in the CVE Program record and NVD vulnerability detail page. Defenders responsible for WordPress sites using the Appointment Booking Plugin, version prior to 5.6.5, should assess exposure and prioritize updating to version 5.6.5 or later to prevent unauthorized deletion of orders, customers, or transactions.
- Vendor
- LatePoint
- Product
- Appointment Booking Plugin
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for WordPress sites using the Appointment Booking Plugin, version prior to 5.6.5, should assess exposure and prioritize updating to version 5.6.5 or later to prevent unauthorized deletion of orders, customers, or transactions.
Why it matters
CVE-2026-105197 is an IDOR vulnerability in the Appointment Booking Plugin for WordPress that allows authenticated staff users to delete unauthorized records. Defenders should prioritize updating to version 5.6.5 or later.
- Potential unauthorized deletion of orders, customers, or transactions
- Possible disruption to business operations and customer data
- Need for verification of staff user authorization for record deletion
- Requirement for updating to version 5.6.5 or later to fix the vulnerability
Technical summary
The Appointment Booking Plugin for WordPress, version prior to 5.6.5, does not verify that a backend staff user is authorized to act on the specific record targeted for deletion. This allows an authenticated user with a record-scoped staff role to irreversibly delete any order, customer, or transaction on the site, including records belonging to other staff and outside their assigned scope. The vulnerability is caused by a lack of proper authorization checks in the plugin's code. Defenders should prioritize updating the Appointment Booking Plugin to version 5.6.5 or later to prevent unauthorized deletion of orders, customers, or transactions.
Defensive priority
Defenders should prioritize updating the Appointment Booking Plugin to version 5.6.5 or later to prevent unauthorized deletion of orders, customers, or transactions.
Recommended defensive actions
- Update Appointment Booking Plugin to version 5.6.5 or later
- Restrict access to sensitive records for staff users with limited roles
- Monitor for suspicious deletion activity on the site
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability was reported by WPScan and documented in the CVE Program record and NVD vulnerability detail page. The source item provides a technical description of the issue. WPScan verified the vulnerability and provided additional details on the affected versions and potential impact. The CVE Program record and NVD vulnerability detail page provide further information on the vulnerability and its potential impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105197 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105197
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105197 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105197
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
LatePoint < 5.6.5 - Agent+ Arbitrary Order, Customer and Transaction Deletion via IDOR
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105197.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/05f690b9-8696-4e73-8f42-f6964db3d092/
Supplemental source - exploit, vdb-entry, technical-description
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.