PT-2026-69170 · WordPress · Appointment Hour Booking
CVE-2026-16282
·
Published
2026-08-08
·
Updated
2026-08-11
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Appointment Hour Booking versions prior to 1.5.88
Description
The plugin fails to validate the booking price provided by the client against the service price configured on the server. This allows unauthenticated users to submit an arbitrary final price, including zero or negative values, via the
tcost parameter. These manipulated values are stored as the authoritative booking price, leading to the corruption of booking and payment records.Recommendations
Update Appointment Hour Booking to version 1.5.88 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Appointment Hour Booking