Vulnerability in Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress — CVE-2026-105196
MediumSeverity
0.1%Estimated exploit probability
100,000+ sitesInstalls
5.6.9Fixed in
What to do now
Update Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress to 5.6.9 or later.
Affected versions
- Everything before 5.6.9
Affected: Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress (plugin, latepoint)
What the vulnerability is
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to 5.6.9. This is due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with custom role-level access and above, to perform an unauthorized action.