CVE-2026-66462: WordPress WooCommerce Appointments plugin <= 5.3.8 - Sensitive Data Exposure vulnerability
Published Aug 13, 2026
·Updated
Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions.
Affected Software
1 affected component
wordpress/woocommerce-appointments<=5.3.8
Event History
Aug 13, 2026
CVE Published
via MITRE·01:37 PM
Data Sourced
via MITRE·01:37 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66462?
The severity of CVE-2026-66462 is rated as high, with a score of 7.5.
2
What type of vulnerability is CVE-2026-66462?
CVE-2026-66462 is classified as an unauthenticated sensitive data exposure vulnerability.
3
How does CVE-2026-66462 affect WordPress WooCommerce Appointments?
CVE-2026-66462 affects versions of the WooCommerce Appointments plugin up to 5.3.8, enabling exposure of sensitive data.
4
How do I fix CVE-2026-66462?
To mitigate CVE-2026-66462, you should update the WooCommerce Appointments plugin to version 5.3.9 or later.
5
What potential impact does CVE-2026-66462 have on my site?
CVE-2026-66462 can lead to exposure of sensitive information from your WordPress site if the plugin is not updated.