PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105197 LatePoint CVE debrief

The Appointment Booking Plugin for WordPress, version prior to 5.6.5, is vulnerable to an insecure direct object reference (IDOR) issue. This allows an authenticated user with a staff role limited to a specific record to delete any order, customer, or transaction on the site, including records outside their assigned scope. The vulnerability was reported by WPScan and documented in the CVE Program record and NVD vulnerability detail page. Defenders responsible for WordPress sites using the Appointment Booking Plugin, version prior to 5.6.5, should assess exposure and prioritize updating to version 5.6.5 or later to prevent unauthorized deletion of orders, customers, or transactions.

Vendor
LatePoint
Product
Appointment Booking Plugin
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for WordPress sites using the Appointment Booking Plugin, version prior to 5.6.5, should assess exposure and prioritize updating to version 5.6.5 or later to prevent unauthorized deletion of orders, customers, or transactions.

Why it matters

CVE-2026-105197 is an IDOR vulnerability in the Appointment Booking Plugin for WordPress that allows authenticated staff users to delete unauthorized records. Defenders should prioritize updating to version 5.6.5 or later.

  • Potential unauthorized deletion of orders, customers, or transactions
  • Possible disruption to business operations and customer data
  • Need for verification of staff user authorization for record deletion
  • Requirement for updating to version 5.6.5 or later to fix the vulnerability

Technical summary

The Appointment Booking Plugin for WordPress, version prior to 5.6.5, does not verify that a backend staff user is authorized to act on the specific record targeted for deletion. This allows an authenticated user with a record-scoped staff role to irreversibly delete any order, customer, or transaction on the site, including records belonging to other staff and outside their assigned scope. The vulnerability is caused by a lack of proper authorization checks in the plugin's code. Defenders should prioritize updating the Appointment Booking Plugin to version 5.6.5 or later to prevent unauthorized deletion of orders, customers, or transactions.

Defensive priority

Defenders should prioritize updating the Appointment Booking Plugin to version 5.6.5 or later to prevent unauthorized deletion of orders, customers, or transactions.

Recommended defensive actions

  • Update Appointment Booking Plugin to version 5.6.5 or later
  • Restrict access to sensitive records for staff users with limited roles
  • Monitor for suspicious deletion activity on the site
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability was reported by WPScan and documented in the CVE Program record and NVD vulnerability detail page. The source item provides a technical description of the issue. WPScan verified the vulnerability and provided additional details on the affected versions and potential impact. The CVE Program record and NVD vulnerability detail page provide further information on the vulnerability and its potential impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105197 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105197

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105197 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105197

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.