CVE-2026-105198: Unknown Appointment Booking Plugin
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The Appointment Booking Plugin WordPress plugin before 5.7.3 does not verify that the caller owns the order referenced by an order-item identifier before rendering that order's confirmation summary, letting an unauthenticated visitor retrieve any customer's name, contact details and order confirmation code by supplying a sequential order-item id.
Affected products
- Unknown Appointment Booking Plugin: before 5.7.3 (fixed in 5.7.3)
Published 2026-10-08. Last modified 2026-10-08.