high · CVSS v3 7.2
CVE-2026-96573
The Appointment Hour Booking – Booking Calendar WordPress plugin is vulnerable to stored DOM‑based XSS via the booking form single‑line fiel
Overview
The Appointment Hour Booking – Booking Calendar WordPress plugin is vulnerable to stored DOM‑based XSS via the booking form single‑line field. Unauthenticated attackers can inject scripts that run for any site visitor when the page is accessed. This flaw exists in all releases up to 1.5.97 and requires the list_readmore_numberofwords setting to be set to a positive integer.
Description
The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer in all versions up to, and including, 1.5.97 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the 'list_readmore_numberofwords' Other Parameters setting to be configured with a positive integer value; the default value of 0 bypasses the decode-and-truncate branch entirely and is not exploitable through this sink.
Impact
Stored DOM‑XSS can lead to session hijacking, defacement, or phishing attacks against site visitors and administrators. The vulnerability compromises confidentiality and integrity of user data and can be used to spread malware. It does not directly affect availability but can degrade user trust.
Remediation
Update the plugin to any version newer than 1.5.97. If an update is not possible, set the list_readmore_numberofwords option to 0 or disable the booking form feature. Additionally, apply a web‑application firewall rule to block script injection in the booking form field.
Risk context
The CVSS v3 score of 7.2 and high severity rating indicate a significant risk. Defenders should prioritize patching or mitigation as soon as possible to prevent exploitation.
Affected products
- WordPress Appointment Hour Booking
- Booking Calendar plugin
Scores
- Severity
- high
- CVSS v2
- 6.4
- CVSS v3
- 7.2
- CVSS v4
- —
- EPSS
- —