Sceawere

Vulnerability Detail

CVE-2026-105197UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Broken Access Control in Appointment Booking

Vulnerability Metadata

Severity
Low
Score / CVSS
2.7
Creation Date
8h ago
Vendor
Unknown
Product
Appointment Booking Plugin
Attack Type
CWE-639 Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Appointment Booking Plugin WordPress plugin before 5.6.5 does not verify that a backend staff user is authorized to act on the specific record targeted for deletion, allowing an authenticated user with a record-scoped staff role to irreversibly delete any order, customer, or transaction on the site, including records belonging to other staff and outside their assigned scope.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "2.7",
  "pubDate": "2026-10-08T06:16:40.553Z",
  "pubdate": "2026-10-08T06:16:40.553Z",
  "executiveSummary": "The Appointment Booking WordPress plugin prior to version 5.6.5 is susceptible to a critical Broken Access Control vulnerability. This flaw stems from improper authorization checks during record deletion operations performed by backend staff users. The vulnerability allows an authenticated user assigned a restricted, record-scoped staff role to bypass intended limitations and execute destructive actions on arbitrary database records. By failing to validate the relationship between the authenticated user's scope and the targeted resource, the application permits unauthorized deletion of orders, customer data, and financial transactions. This security deficiency poses a significant risk to data integrity and business operations, as it grants malicious or compromised staff accounts the ability to permanently purge sensitive information belonging to other staff members or customers outside their authorized scope. Exploitation requires authenticated access with a staff-level role, but requires no additional privileges beyond the assigned scope to execute the unauthorized deletion of site-wide data.",
  "technicalDetails": "The root cause of this vulnerability is an Insecure Direct Object Reference (IDOR) condition combined with insufficient authorization validation within the plugin's backend request handling logic. Specifically, the component responsible for processing record deletion requests fails to implement a server-side check to verify that the requesting user's session possesses the requisite permissions to modify or delete the specific resource identifier provided in the request payload.\nIn a secure implementation, the plugin should perform a cross-reference between the current user's assigned scope (the specific records they are authorized to manage) and the Unique Identifier (UID) of the record being targeted for deletion. The current implementation erroneously assumes that authentication as a backend staff member is sufficient authorization to perform destructive operations on any record accessible via the plugin's API or controller functions.\nThe attack flow proceeds as follows: An authenticated user with restricted staff privileges identifies the API endpoint or administrative action used for deleting resources such as appointments, customer profiles, or transaction logs. By intercepting or crafting a request—typically by manipulating the primary key or unique identifier parameter within the request body—the attacker targets records that fall outside their assigned scope. Because the backend logic lacks an object-level authorization check, the server processes the deletion request directly upon verifying that the user is authenticated as a staff member. The database layer executes the delete command against the target record regardless of the user's lack of ownership or administrative authority over that specific record.\nThis vulnerability is present in all versions of the Appointment Booking plugin prior to 5.6.5. The impact of successful exploitation is high, as it enables an attacker to conduct a mass deletion of site data, leading to severe disruption of services, loss of customer history, and potential regulatory implications due to the unauthorized destruction of transactional and personal identifiable information. Because the operation is irreversible, the impact is immediate and damaging, necessitating robust access control validation to ensure that all database interactions are bounded by the user's authorized scope and session context."
}
CVE-2026-105197: Broken Access Control in Appointment Booking (LOW Severity, CVSS: 2.7) | Sceawere