Description


The Appointment Booking Plugin WordPress plugin before 5.6.9 does not enforce per-record authorization on several of its AI Abilities API actions, allowing an authenticated user holding the LatePoint Agent role, normally restricted to their own records, to read and modify other agents' profile data and read other agents' bookings and associated customer details when the Abilities API feature is enabled.

Related CPE's


Could not find any relations

Weaknesses


134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-639

CVSS impact metrics


CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N

3.3 · Low

Information


Source identifier

[email protected]

Vulnerability status

Deferred

Published

2026-10-08T06:16:40.250Z

26 hours ago

Last modified

2026-10-08T20:51:18.123Z

12 hours ago