CVE-2026-86475
Appointment Hour Booking < 1.5.95 - Unauthenticated Booking Capacity Bypass via Multi-Appointment Submission
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission against the capacity configured for its own slot, allowing unauthenticated visitors to take slots that are already fully booked.
| Vendor | unknown |
| Product | appointment hour booking |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown appointment hour booking
Be the first to know when new medium vulnerabilities affecting unknown appointment hour booking are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Unknown / Appointment Hour Booking
0 < 1.5.95
References
Credits
Nicat WPScan