CVE-2026-86475

Summary

The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission against the capacity configured for its own slot, allowing unauthenticated visitors to take slots that are already fully booked.

Affected Software

VendorProductVersion RangeStatus
UnknownAppointment Hour Booking0 < 1.5.95affected

Weaknesses

  • CWE-20 Improper Input Validation

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: yes
    • Technical Impact: partial

References