Stored DOM-Based Cross-Site Scripting Vulnerability in Appointment Hour Booking Plugin for WordPress
CVE-2026-96573

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 October 2026

What is CVE-2026-96573?

The Appointment Hour Booking – Booking Calendar plugin for WordPress has a vulnerability allowing unauthenticated attackers to exploit stored DOM-based cross-site scripting. This occurs through the Booking Form Single-Line Field via the Schedule Calendar List Renderer, specifically in all versions up to and including 1.5.97. Due to inadequate input sanitization and output escaping, attackers can inject arbitrary web scripts. When exploited, this vulnerability can lead to scripts executing in the context of a user’s session whenever the infected page is accessed. The attack becomes possible when the 'list_readmore_numberofwords' parameter is set to a positive integer, allowing for manipulation that circumvents the default behavior, which is not exploitable.

Affected Version(s)

Appointment Hour Booking – Booking Calendar 0 <= 1.5.97

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zackary Loevseth
.