CVE-2026-86475

The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission against the capacity configured for its own slot, allowing unauthenticated visitors to take slots that are already fully booked.
Configurations

No configuration.

History

16 Sep 2026, 18:17

Type Values Removed Values Added
CWE CWE-20

Information

Published : 2026-09-16 07:16

Updated : 2026-09-16 20:25


NVD link : CVE-2026-86475

Mitre link : CVE-2026-86475

CVE.ORG link : CVE-2026-86475


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation