Sceawere

Vulnerability Detail

CVE-2026-105196UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

LatePoint Broken Object Level Authorization

Vulnerability Metadata

Severity
Low
Score / CVSS
3.3
Creation Date
8h ago
Vendor
Unknown
Product
Appointment Booking Plugin
Attack Type
CWE-639 Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

The Appointment Booking Plugin WordPress plugin before 5.6.9 does not enforce per-record authorization on several of its AI Abilities API actions, allowing an authenticated user holding the LatePoint Agent role, normally restricted to their own records, to read and modify other agents' profile data and read other agents' bookings and associated customer details when the Abilities API feature is enabled.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.3",
  "pubDate": "2026-10-08T06:16:40.250Z",
  "pubdate": "2026-10-08T06:16:40.250Z",
  "executiveSummary": "The Appointment Booking Plugin for WordPress, in versions prior to 5.6.9, contains a critical Broken Object Level Authorization (BOLA) vulnerability within its AI Abilities API module.\nThe vulnerability allows authenticated users assigned the 'LatePoint Agent' role to bypass intended access control restrictions.\nUnder normal operating conditions, agents are restricted to managing their own records; however, this flaw enables unauthorized read and modification operations on arbitrary agents' profiles, booking records, and associated customer sensitive information.\nThe vulnerability stems from the application's failure to perform adequate server-side authorization checks on requested resources via the API endpoints.\nAn attacker with low-privileged 'LatePoint Agent' access can enumerate or manipulate the records of other agents, leading to unauthorized data exposure and modification.\nThe risk implication is significant as it facilitates unauthorized access to private customer data and administrative business information, potentially violating data privacy regulations.\nExploitation requires an active, authenticated session with the 'LatePoint Agent' role and the 'AI Abilities API' feature to be explicitly enabled.",
  "technicalDetails": "The vulnerability is classified as a Broken Object Level Authorization (BOLA) issue, specifically occurring within the AI Abilities API functionality of the Appointment Booking Plugin.\nThe root cause is the absence of rigorous per-record authorization validation on API requests. When the AI Abilities API is enabled, the plugin exposes endpoints intended for agent management. While the system expects these requests to be scoped to the authenticated user's ID, the application fails to verify if the requested object (agent profile, booking ID, or customer data) is owned by or assigned to the requester.\nThe attack flow proceeds as follows: An authenticated user with the 'LatePoint Agent' role initiates a request to the vulnerable API endpoints. Because the backend processes these requests without verifying the relationship between the authenticated session user and the object ID provided in the request parameters, the system processes the query regardless of record ownership.\nAn attacker can manipulate the request parameters—such as agent_id or booking_id—to target resources belonging to other agents or customers. By systematically incrementing or brute-forcing these identifiers, an attacker can scrape the entirety of the plugin's booking database, retrieve private customer contact information, or modify the appointment profiles of their peers.\nThe lack of server-side validation during the handling of these API calls bypasses the logic implemented in the standard WordPress user role management system, effectively elevating the privileges of a low-level agent to that of a system-wide read/write operator within the context of the plugin's data model.\nAffected versions include all iterations of the Appointment Booking Plugin prior to 5.6.9. The vulnerability is network-exposed, requiring no specific proximity to the server, provided the attacker has valid credentials and the targeted features are active.\nPost-exploitation, the impact is severe, resulting in unauthorized data exfiltration, loss of data integrity via unauthorized modifications to booking records, and potential privacy compliance failures concerning the sensitive customer information managed through the plugin."
}
CVE-2026-105196: LatePoint Broken Object Level Authorization (LOW Severity, CVSS: 3.3) | Sceawere