Get real-time updates on Telegram
Verified
CVE-2026-105197: Appointment Booking Plugin 0 to before 5.6.5
Affected technology
Appointment Booking Plugin · 0 to before 5.6.5
Vendor not specified by the source
Description’s affected range: before 5.6.5 does not verify that a backend staff user is authorized to act on the specific record targeted for deletion
Component: Not specified by the source
What an attacker can do
An authenticated user with a record-scoped staff role can irreversibly delete any order, customer, or transaction on the site, including records belonging to other staff and outside their assigned scope.
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-08 08:50:52.119177+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 08:49:39.219831+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-105197.html