CVE-2026-16282 PUBLISHED

Appointment Hour Booking < 1.5.88 - Unauthenticated Booking Price Manipulation via tcost Parameter

Assigner: WPScan
Reserved: 20.07.2026 Published: 08.08.2026 Updated: 08.08.2026

The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured service price, allowing unauthenticated users to submit an arbitrary final price (including zero or negative) that is stored as the authoritative booking price, corrupting booking and payment records.

Product Status

Vendor Unknown
Product Appointment Hour Booking
Versions Default: unaffected
  • affected from 0 to 1.5.88 (excl.)

Credits

  • Researcher1: Alessandro Greco aka Aleff; Researcher2: Giovambattista Ianni; Company/Organization: University of Calabria (UNICAL) finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE