CVE-2026-105196

CVE-2026-105196 published: The Appointment Booking Plugin WordPress plugin before 5.6.9 does not enforce per-record authorization on several of its AI Abilities API actions, allowing an authenticated user holding the LatePoint Agent role, normally restricted to their own records, to...

View full NVD advisory → ← Back to CVE watch