AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16282

MEDIUM · CVSS 5.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-08 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Appointment Hour Booking WordPress plugin prior to version 1.5.88 is vulnerable due to inadequate validation of client-supplied booking prices, allowing unauthenticated users to set arbitrary final prices, including zero or negative values. This flaw can lead to corruption of booking and payment records, potentially resulting in financial loss and operational disruptions. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-16282
Severity
MEDIUM
CVSS
5.3
EPSS
0.18%
WordPress

Original NVD Description

The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured service price, allowing unauthenticated users to submit an arbitrary final price (including zero or negative) that is stored as the authoritative booking price, corrupting booking and payment records.