Arbitrary Pricing Vulnerability in Appointment Hour Booking Plugin for WordPress
CVE-2026-16282

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
8 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-16282?

The Appointment Hour Booking plugin for WordPress contains a flaw that allows unauthenticated users to submit a booking price that is not validated against the server-side configured service price. This lack of validation means users can set any final price, including zero or negative values, which can corrupt booking and payment records. Prompt updates to the plugin are advisable to mitigate the risk of exploitation.

Affected Version(s)

Appointment Hour Booking 0 < 1.5.88

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Researcher1: Alessandro Greco aka Aleff; Researcher2: Giovambattista Ianni; Company/Organization: University of Calabria (UNICAL)
WPScan
.