Appointment Hour Booking – Booking Calendar <= 1.5.91 - Missing Authorization
medium
The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.5.91. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.5.91
- Fix:
- No patched version reported
- Disclosed:
- Aug 18, 2026
CVE-2026-66679 on NVD →
Appointment Hour Booking <= 1.5.87 - Unauthenticated Price Manipulation
medium
The Appointment Hour Booking plugin for WordPress is vulnerable to Price Manipulation in versions up to, and including, 1.5.87. This is due to the extract_appointments function accepting a user-supplied price via the tcost parameter (stored as $fieldpostedcost) and assigning it directly to the booking record, exploitab...
- CVSS:
- 5.3
- Affected:
- up to 1.5.87
- Fixed in:
- 1.5.88
- Disclosed:
- Aug 3, 2026
CVE-2026-16282 on NVD →
Appointment Hour Booking – Booking Calendar <= 1.5.86 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject ar...
- CVSS:
- 6.4
- Affected:
- up to 1.5.86
- Fixed in:
- 1.5.87
- Disclosed:
- Jul 23, 2026
CVE-2026-65514 on NVD →
Appointment Hour Booking – Booking Calendar <= 1.5.60 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Min/Max Length' Field Configuration
medium
The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form field configuration parameters in all versions up to, and including, 1.5.60 due to insufficient input sanitization and output escaping on the 'Min length/characters' and 'Max length/characters' fie...
- CVSS:
- 4.4
- Affected:
- up to 1.5.60
- Fixed in:
- 1.5.61
- Disclosed:
- Jan 27, 2026
CVE-2026-1083 on NVD →
Appointment Hour Booking <= 1.4.56 - Captcha Bypass
medium
The Appointment Hour Booking plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 1.4.56. This makes it possible for unauthenticated attackers to bypass the Captcha Verification.
- CVSS:
- 5.3
- Affected:
- up to 1.4.56
- Fixed in:
- 1.4.57
- Disclosed:
- Apr 22, 2024
CVE-2024-32720 on NVD →
Appointment Hour Booking <= 1.4.23 - Missing Authorization to Double Booking
medium
The Appointment Hour Booking plugin for WordPress is vulnerable to unauthorized double booking due to insufficient validation on the data_management() function in versions up to, and including, 1.4.23. This makes it possible for unauthenticated attackers to make double bookings.
- CVSS:
- 5.3
- Affected:
- up to 1.4.23
- Fixed in:
- 1.4.24
- Disclosed:
- Oct 11, 2023
CVE-2023-45649 on NVD →
Appointment Hour Booking <= 1.3.72 - Unauthenticated iFrame Injection via Appointment Form
high
The Appointment Hour Booking plugin for WordPress is vulnerable to iFrame Injection via the ‘email’ or general field parameters in versions up to, and including, 1.3.72 due to insufficient input sanitization and output escaping that makes injecting iFrame tags possible. This makes it possible for unauthenticated attack...
- CVSS:
- 7.2
- Affected:
- up to 1.3.72
- Fixed in:
- 1.3.73
- Disclosed:
- Nov 29, 2022
CVE-2022-4035 on NVD →
Appointment Hour Booking <= 1.3.72 - CSV Injection
medium
The Appointment Hour Booking Plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3.72. This makes it possible for unauthenticated attackers to embed untrusted input into content during booking creation that may be exported as a CSV file when a site's administrator exports booking det...
- CVSS:
- 5.8
- Affected:
- up to 1.3.72
- Fixed in:
- 1.3.73
- Disclosed:
- Nov 29, 2022
CVE-2022-4034 on NVD →
Appointment Hour Booking <= 1.3.72 - CAPTCHA Bypass
medium
The Appointment Hour Booking plugin for WordPress is vulnerable to CAPTCHA bypass in versions up to, and including, 1.3.72. This is due to the use of insufficiently strong hashing algorithm on the CAPTCHA secret that is also displayed to the user via a cookie.
- CVSS:
- 5.3
- Affected:
- up to 1.3.72
- Fixed in:
- 1.3.73
- Disclosed:
- Nov 29, 2022
CVE-2022-4036 on NVD →
Appointment Hour Booking <= 1.3.71 - Missing Authorization
medium
The Appointment Hour Booking plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the cpapphb_feedback function in versions up to, and including, 1.3.71. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to provide plugin feedback...
- CVSS:
- 4.3
- Affected:
- up to 1.3.71
- Fixed in:
- 1.3.72
- Disclosed:
- Oct 30, 2022
CVE-2022-41692 on NVD →
Appointment Hour Booking <= 1.3.55 - Authenticated Stored Cross-Site Scripting
medium
The Appointment Hour Booking WordPress plugin before 1.3.56 does not sanitise and escape a settings of its Calendar fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
- CVSS:
- 4.8
- Affected:
- up to 1.3.55
- Fixed in:
- 1.3.56
- Disclosed:
- May 23, 2022
CVE-2022-1710 on NVD →
Appointment Hour Booking <= 1.3.16 - Cross-Site Scripting
medium
The Appointment Hour Booking WordPress plugin before 1.3.17 does not properly sanitize values used when creating new calendars.
- CVSS:
- 6.4
- Affected:
- up to 1.3.17
- Fixed in:
- 1.3.17
- Disclosed:
- Sep 10, 2021
CVE-2021-24712 on NVD →
Appointment Hour Booking <= 1.3.15 Admin+ Stored Cross-Site Scripting
medium
The Appointment Hour Booking WordPress plugin before 1.3.16 does not escape some of the Calendar Form settings, allowing high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- CVSS:
- 5.5
- Affected:
- up to 1.3.16
- Fixed in:
- 1.3.16
- Disclosed:
- Sep 6, 2021
CVE-2021-24673 on NVD →
Appointment Hour Booking – WordPress Booking Plugin <= 1.1.45 - Cross-Site Scripting
medium
The Appointment Hour Booking plugin 1.1.44 for WordPress allows XSS via the E-mail field, as demonstrated by email_1.
- CVSS:
- 6.1
- Affected:
- up to 1.1.46
- Fixed in:
- 1.1.46
- Disclosed:
- Jul 9, 2019
CVE-2019-13505 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database