CVE-2026-66679: WordPress Appointment Hour Booking plugin <= 1.5.91 - Broken Access Control vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions.
Affected Software
1 affected component
wordpress-plugin/appointment-hour-booking<=1.5.91
Event History
Aug 18, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed?
Sites using Appointment Hour Booking version 1.5.91 or earlier are affected according to the available information. The issue is reachable over the network and requires no authentication or user interaction.
2
What does an attacker need to exploit this issue?
An unauthenticated attacker can exploit the broken access control condition without needing an account or victim interaction. The reported impact is limited to integrity and availability; no confidentiality impact is listed.