Stored DOM-Based Cross-Site Scripting Vulnerability in Appointment Hour Booking Plugin for WordPress
CVE-2026-96573
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-96573?
The Appointment Hour Booking – Booking Calendar plugin for WordPress has a vulnerability allowing unauthenticated attackers to exploit stored DOM-based cross-site scripting. This occurs through the Booking Form Single-Line Field via the Schedule Calendar List Renderer, specifically in all versions up to and including 1.5.97. Due to inadequate input sanitization and output escaping, attackers can inject arbitrary web scripts. When exploited, this vulnerability can lead to scripts executing in the context of a user’s session whenever the infected page is accessed. The attack becomes possible when the 'list_readmore_numberofwords' parameter is set to a positive integer, allowing for manipulation that circumvents the default behavior, which is not exploitable.
Affected Version(s)
Appointment Hour Booking – Booking Calendar 0 <= 1.5.97