GHSA-r9q4-xcm5-g5wwMediumCVSS 5.3

The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied...

Published
August 8, 2026
Last Modified
August 11, 2026

🔗 CVE IDs covered (1)

📋 Description

The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured service price, allowing unauthenticated users to submit an arbitrary final price (including zero or negative) that is stored as the authoritative booking price, corrupting booking and payment records.

🔗 References (3)