Description
The Appointment Booking Plugin WordPress plugin before 5.6.9 does not enforce per-record authorization on several of its AI Abilities API actions, allowing an authenticated user holding the LatePoint Agent role, normally restricted to their own records, to read and modify other agents' profile data and read other agents' bookings and associated customer details when the Abilities API feature is enabled.
Related CPE's
Could not find any relations
Weaknesses
134c704f-9b21-4f2e-91b3-4a467353bcc0
Secondary
CWE-639
CVSS impact metrics
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
3.3 · Low
Information
Source identifier
Vulnerability status
Deferred
Published
2026-10-08T06:16:40.250Z
26 hours agoLast modified
2026-10-08T20:51:18.123Z
12 hours ago