Vulnerability in Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress — CVE-2026-105198
MediumSeverity
0.2%Estimated exploit probability
100,000+ sitesInstalls
5.7.3Fixed in
What to do now
Update Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress to 5.7.3 or later.
Affected versions
- Everything before 5.7.3
Affected: Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress (plugin, latepoint)
What the vulnerability is
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to 5.7.3. This is due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.