---
id: CVE-2026-105198
title: >-
  The Appointment Booking Plugin  WordPress plugin before 5.7.3 does not verify
  that the caller owns the order referenced by an order-item identifier before
  rendering that order's confirmation summary, letting an unauthenticated
  visitor re…
summary: >-
  The Appointment Booking Plugin  WordPress plugin before 5.7.3 does not verify
  that the caller owns the order referenced by an order-item identifier before
  rendering that order's confirmation summary, letting an unauthenticated
  visitor re…
severity: none
cwe:
  - CWE-639
product: Appointment Booking Plugin
affected:
  - appointment_booking_plugin < 5.7.3
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T06:16:40.873'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105198'
references:
  - url: 'https://wpscan.com/vulnerability/736056ca-5825-4cb7-8775-4010efe1f7cd/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-08T07:18:54.840Z'
---

## Overview

The Appointment Booking Plugin  WordPress plugin before 5.7.3 does not verify that the caller owns the order referenced by an order-item identifier before rendering that order's confirmation summary, letting an unauthenticated visitor retrieve any customer's name, contact details and order confirmation code by supplying a sequential order-item id.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
