NONE · 0

CVE-2026-16282

The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured service price, allowing unauthenticated users to submi...

Vulnerability Description

The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured service price, allowing unauthenticated users to submit an arbitrary final price (including zero or negative) that is stored as the authoritative booking price, corrupting booking and payment records.

References

FAQ

What is CVE-2026-16282?

CVE-2026-16282 is a documented vulnerability. The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured service price, allowing unauthenticated users to submi...

How severe is CVE-2026-16282?

CVSS scoring is not yet available for CVE-2026-16282. Check NVD for updates.

Is there a patch for CVE-2026-16282?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.