CVE-2026-86475

MEDIUM Status: Received

CVSS Scores

CVSS v3.x Base Score
5.3
MEDIUM

Description

The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission against the capacity configured for its own slot, allowing unauthenticated visitors to take slots that are already fully booked.

Published
September 16, 2026 7:16 AM
Last Modified
September 16, 2026 7:16 AM
Source
[email protected]

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.