rootpwn

high · CVSS v3 7.2

CVE-2026-96573

The Appointment Hour Booking – Booking Calendar WordPress plugin is vulnerable to stored DOM‑based XSS via the booking form single‑line fiel

Overview

The Appointment Hour Booking – Booking Calendar WordPress plugin is vulnerable to stored DOM‑based XSS via the booking form single‑line field. Unauthenticated attackers can inject scripts that run for any site visitor when the page is accessed. This flaw exists in all releases up to 1.5.97 and requires the list_readmore_numberofwords setting to be set to a positive integer.

Description

The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer in all versions up to, and including, 1.5.97 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the 'list_readmore_numberofwords' Other Parameters setting to be configured with a positive integer value; the default value of 0 bypasses the decode-and-truncate branch entirely and is not exploitable through this sink.

Impact

Stored DOM‑XSS can lead to session hijacking, defacement, or phishing attacks against site visitors and administrators. The vulnerability compromises confidentiality and integrity of user data and can be used to spread malware. It does not directly affect availability but can degrade user trust.

Remediation

Update the plugin to any version newer than 1.5.97. If an update is not possible, set the list_readmore_numberofwords option to 0 or disable the booking form feature. Additionally, apply a web‑application firewall rule to block script injection in the booking form field.

Risk context

The CVSS v3 score of 7.2 and high severity rating indicate a significant risk. Defenders should prioritize patching or mitigation as soon as possible to prevent exploitation.

Affected products

  • WordPress Appointment Hour Booking
  • Booking Calendar plugin

Scores

Severity
high
CVSS v2
6.4
CVSS v3
7.2
CVSS v4
—
EPSS
—

XSS WordPress StoredXSS BookingCalendar HighSeverity InputSanitization

← All CVEs