PT-2026-107835 · WordPress · Appointment Hour Booking Plugin
CVSS v3.1
3.3
Low
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Appointment Booking Plugin WordPress plugin versions prior to 5.6.9
Description
Insufficient per-record authorization in several AI Abilities API actions allows an authenticated user with the LatePoint Agent role to bypass restrictions. When the Abilities API feature is enabled, an attacker can read and modify profile data of other agents, as well as access bookings and associated customer details belonging to other agents.
Recommendations
Update the Appointment Booking Plugin to version 5.6.9 or later.
As a temporary mitigation, disable the Abilities API feature.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Appointment Hour Booking Plugin