Vulnerability in Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress — CVE-2026-105197
MediumSeverity
0.2%Estimated exploit probability
100,000+ sitesInstalls
5.6.5Fixed in
What to do now
Update Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress to 5.6.5 or later.
Affected versions
- Everything before 5.6.5
Affected: Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress (plugin, latepoint)
What the vulnerability is
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to 5.6.5. This is due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with custom role-level access and above, to perform an unauthorized action.