plugin

Appointment Hour Booking Vulnerabilities

14 known security issues reported for the Appointment Hour Booking WordPress plugin. Most recent disclosed Aug 18, 2026.

1 high 13 medium

Running Appointment Hour Booking on your site? Check whether your installed version is affected.

Scan your site free

Appointment Hour Booking – Booking Calendar <= 1.5.91 - Missing Authorization

medium

The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.5.91. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.5.91
Fix:
No patched version reported
Disclosed:
Aug 18, 2026

CVE-2026-66679 on NVD →

Appointment Hour Booking <= 1.5.87 - Unauthenticated Price Manipulation

medium

The Appointment Hour Booking plugin for WordPress is vulnerable to Price Manipulation in versions up to, and including, 1.5.87. This is due to the extract_appointments function accepting a user-supplied price via the tcost parameter (stored as $fieldpostedcost) and assigning it directly to the booking record, exploitab...

CVSS:
5.3
Affected:
up to 1.5.87
Fixed in:
1.5.88
Disclosed:
Aug 3, 2026

CVE-2026-16282 on NVD →

Appointment Hour Booking – Booking Calendar <= 1.5.86 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject ar...

CVSS:
6.4
Affected:
up to 1.5.86
Fixed in:
1.5.87
Disclosed:
Jul 23, 2026

CVE-2026-65514 on NVD →

Appointment Hour Booking – Booking Calendar <= 1.5.60 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Min/Max Length' Field Configuration

medium

The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form field configuration parameters in all versions up to, and including, 1.5.60 due to insufficient input sanitization and output escaping on the 'Min length/characters' and 'Max length/characters' fie...

CVSS:
4.4
Affected:
up to 1.5.60
Fixed in:
1.5.61
Disclosed:
Jan 27, 2026

CVE-2026-1083 on NVD →

Appointment Hour Booking <= 1.4.56 - Captcha Bypass

medium

The Appointment Hour Booking plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 1.4.56. This makes it possible for unauthenticated attackers to bypass the Captcha Verification.

CVSS:
5.3
Affected:
up to 1.4.56
Fixed in:
1.4.57
Disclosed:
Apr 22, 2024

CVE-2024-32720 on NVD →

Appointment Hour Booking <= 1.4.23 - Missing Authorization to Double Booking

medium

The Appointment Hour Booking plugin for WordPress is vulnerable to unauthorized double booking due to insufficient validation on the data_management() function in versions up to, and including, 1.4.23. This makes it possible for unauthenticated attackers to make double bookings.

CVSS:
5.3
Affected:
up to 1.4.23
Fixed in:
1.4.24
Disclosed:
Oct 11, 2023

CVE-2023-45649 on NVD →

Appointment Hour Booking <= 1.3.72 - Unauthenticated iFrame Injection via Appointment Form

high

The Appointment Hour Booking plugin for WordPress is vulnerable to iFrame Injection via the ‘email’ or general field parameters in versions up to, and including, 1.3.72 due to insufficient input sanitization and output escaping that makes injecting iFrame tags possible. This makes it possible for unauthenticated attack...

CVSS:
7.2
Affected:
up to 1.3.72
Fixed in:
1.3.73
Disclosed:
Nov 29, 2022

CVE-2022-4035 on NVD →

Appointment Hour Booking <= 1.3.72 - CSV Injection

medium

The Appointment Hour Booking Plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3.72. This makes it possible for unauthenticated attackers to embed untrusted input into content during booking creation that may be exported as a CSV file when a site's administrator exports booking det...

CVSS:
5.8
Affected:
up to 1.3.72
Fixed in:
1.3.73
Disclosed:
Nov 29, 2022

CVE-2022-4034 on NVD →

Appointment Hour Booking <= 1.3.72 - CAPTCHA Bypass

medium

The Appointment Hour Booking plugin for WordPress is vulnerable to CAPTCHA bypass in versions up to, and including, 1.3.72. This is due to the use of insufficiently strong hashing algorithm on the CAPTCHA secret that is also displayed to the user via a cookie.

CVSS:
5.3
Affected:
up to 1.3.72
Fixed in:
1.3.73
Disclosed:
Nov 29, 2022

CVE-2022-4036 on NVD →

Appointment Hour Booking <= 1.3.71 - Missing Authorization

medium

The Appointment Hour Booking plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the cpapphb_feedback function in versions up to, and including, 1.3.71. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to provide plugin feedback...

CVSS:
4.3
Affected:
up to 1.3.71
Fixed in:
1.3.72
Disclosed:
Oct 30, 2022

CVE-2022-41692 on NVD →

Appointment Hour Booking <= 1.3.55 - Authenticated Stored Cross-Site Scripting

medium

The Appointment Hour Booking WordPress plugin before 1.3.56 does not sanitise and escape a settings of its Calendar fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

CVSS:
4.8
Affected:
up to 1.3.55
Fixed in:
1.3.56
Disclosed:
May 23, 2022

CVE-2022-1710 on NVD →

Appointment Hour Booking <= 1.3.16 - Cross-Site Scripting

medium

The Appointment Hour Booking WordPress plugin before 1.3.17 does not properly sanitize values used when creating new calendars.

CVSS:
6.4
Affected:
up to 1.3.17
Fixed in:
1.3.17
Disclosed:
Sep 10, 2021

CVE-2021-24712 on NVD →

Appointment Hour Booking <= 1.3.15 Admin+ Stored Cross-Site Scripting

medium

The Appointment Hour Booking WordPress plugin before 1.3.16 does not escape some of the Calendar Form settings, allowing high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS:
5.5
Affected:
up to 1.3.16
Fixed in:
1.3.16
Disclosed:
Sep 6, 2021

CVE-2021-24673 on NVD →

Appointment Hour Booking – WordPress Booking Plugin <= 1.1.45 - Cross-Site Scripting

medium

The Appointment Hour Booking plugin 1.1.44 for WordPress allows XSS via the E-mail field, as demonstrated by email_1.

CVSS:
6.1
Affected:
up to 1.1.46
Fixed in:
1.1.46
Disclosed:
Jul 9, 2019

CVE-2019-13505 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database