CVE-2026-86475: Appointment Hour Booking < 1.5.95 - Unauthenticated Booking Capacity Bypass via Multi-Appointment Submission
The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission against the capacity configured for its own slot, allowing unauthenticated visitors to take slots that are already fully booked.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Appointment Hour Booking WordPress pluginto a version that resolves this vulnerability.Fixed in 1.5.95 - Compensating control
Restrict unauthenticated access to the Appointment Hour Booking booking submission endpoint until the plugin is upgraded to 1.5.95.
Event History
Frequently Asked Questions
Which deployments are exposed?
WordPress sites using Appointment Hour Booking versions earlier than 1.5.95 are affected. The issue concerns booking submissions containing multiple appointments.
Does exploitation require an account or user interaction?
No. An unauthenticated visitor can exploit the issue remotely, and no user interaction is required.
What is the practical impact of exploitation?
An attacker can take appointment slots that are already fully booked by bypassing the configured capacity checks for individual slots.