Unrated severityNVD Advisory· Published Oct 8, 2026
CVE-2026-105197
CVE-2026-105197
Description
The Appointment Booking Plugin WordPress plugin before 5.6.5 does not verify that a backend staff user is authorized to act on the specific record targeted for deletion, allowing an authenticated user with a record-scoped staff role to irreversibly delete any order, customer, or transaction on the site, including records belonging to other staff and outside their assigned scope.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <5.6.5
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.