CVE-2026-105196: LatePoint < 5.6.9 - Agent+ Cross-Agent Data Disclosure and Modification via Abilities API
The Appointment Booking Plugin WordPress plugin before 5.6.9 does not enforce per-record authorization on several of its AI Abilities API actions, allowing an authenticated user holding the LatePoint Agent role, normally restricted to their own records, to read and modify other agents' profile data and read other agents' bookings and associated customer details when the Abilities API feature is enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
LatePointto a version that resolves this vulnerability.Fixed in 5.6.9
Event History
Frequently Asked Questions
Who is exposed to this issue?
Sites using the LatePoint WordPress plugin before 5.6.9 are exposed only when the Abilities API feature is enabled. Exploitation requires an authenticated user with the LatePoint Agent role.
What access does an attacker gain?
A LatePoint Agent can read and modify profile data belonging to other agents. They can also read other agents' bookings and associated customer details.
Is unauthenticated exploitation possible?
No. The provided CVSS vector requires high privileges, and the description specifically requires an authenticated user holding the LatePoint Agent role.
What should be prioritized for remediation?
Update LatePoint to version 5.6.9 or later. If updating cannot happen immediately, disabling the Abilities API feature removes the feature condition described for exploitation.