Junglewise Threat Intelligence

CVE-2026-86475: Appointment Hour Booking booking capacity bypass

CVE-2026-86475 · Severity: medium · CVSS 5.3 · Published 2026-09-16

Executive brief

Appointment Hour Booking is a WordPress plugin that allows websites to accept appointment bookings with capacity limits per time slot. An attacker can bypass the capacity restrictions and book slots that are already fully booked by submitting multiple appointments in a single submission, without requiring authentication.

Technical details

The plugin fails to validate every appointment in a multi-appointment booking submission against the capacity configured for each slot. This is a logic flaw in the booking validation routine. An unauthenticated attacker can exploit this by crafting a booking request containing multiple appointments and bypassing capacity checks for individual slots. The attack requires network access to the WordPress site and no authentication. An attacker can overbook appointment slots, degrading service availability and customer experience. The vulnerability was fixed in version 1.5.95.

Affected products

  • Appointment Hour Booking Appointment Hour Booking before 1.5.95

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixed in version 1.5.95

References