CVE-2026-16282
Appointment Hour Booking < 1.5.88 - Unauthenticated Booking Price Manipulation via tcost Parameter
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured service price, allowing unauthenticated users to submit an arbitrary final price (including zero or negative) that is stored as the authoritative booking price, corrupting booking and payment records.
| Vendor | unknown |
| Product | appointment hour booking |
| Published | Aug 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown appointment hour booking
Be the first to know when new unknown vulnerabilities affecting unknown appointment hour booking are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Appointment Hour Booking
0 < 1.5.88
References
Credits
Researcher1: Alessandro Greco aka Aleff; Researcher2: Giovambattista Ianni; Company/Organization: University of Calabria (UNICAL) WPScan