{"api_version":"1","generated_at":"2026-10-02T23:34:21+00:00","cve":"CVE-2026-96573","urls":{"html":"https://cve.report/CVE-2026-96573","api":"https://cve.report/api/cve/CVE-2026-96573.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-96573","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-96573"},"summary":{"title":"Appointment Hour Booking <= 1.5.97 - Unauthenticated Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer","description":"The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer in all versions up to, and including, 1.5.97 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the 'list_readmore_numberofwords' Other Parameters setting to be configured with a positive integer value; the default value of 0 bypasses the decode-and-truncate branch entirely and is not exploitable through this sink.","state":"PUBLISHED","assigner":"Wordfence","published_at":"2026-10-01 09:17:10","updated_at":"2026-10-01 15:17:37"},"problem_types":["CWE-79","CWE-79 CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"],"metrics":[{"version":"3.1","source":"security@wordfence.com","type":"Secondary","score":"7.2","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.2","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","data":{"baseScore":7.2,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/appointment-hour-booking/tags/1.5.97/classes/cp-base-class.inc.php#L81","name":"https://plugins.trac.wordpress.org/browser/appointment-hour-booking/tags/1.5.97/classes/cp-base-class.inc.php#L81","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3044e60f-b930-42db-ba5d-656e71b84226?source=cve","name":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3044e60f-b930-42db-ba5d-656e71b84226?source=cve","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/browser/appointment-hour-booking/tags/1.5.97/cp-main-class.inc.php#L1745","name":"https://plugins.trac.wordpress.org/browser/appointment-hour-booking/tags/1.5.97/cp-main-class.inc.php#L1745","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/browser/appointment-hour-booking/tags/1.5.97/mv/js/jquery.calendar.js","name":"https://plugins.trac.wordpress.org/browser/appointment-hour-booking/tags/1.5.97/mv/js/jquery.calendar.js","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/browser/appointment-hour-booking/tags/1.5.97/cp-main-class.inc.php#L1473","name":"https://plugins.trac.wordpress.org/browser/appointment-hour-booking/tags/1.5.97/cp-main-class.inc.php#L1473","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/browser/appointment-hour-booking/tags/1.5.97/cp-main-class.inc.php#L1609","name":"https://plugins.trac.wordpress.org/browser/appointment-hour-booking/tags/1.5.97/cp-main-class.inc.php#L1609","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3718725%40appointment-hour-booking&new=3718725%40appointment-hour-booking","name":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3718725%40appointment-hour-booking&new=3718725%40appointment-hour-booking","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-96573","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-96573","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"codepeople","product":"Appointment Hour Booking – Booking Calendar","version":"affected 1.5.97 semver","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-09-23T13:43:40.000Z","lang":"en","value":"Vendor Notified"},{"source":"CNA","time":"2026-09-30T20:09:56.000Z","lang":"en","value":"Disclosed"}],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Zackary Loevseth","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-96573","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-10-01T14:13:16.706277Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-10-01T14:13:25.726Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Appointment Hour Booking – Booking Calendar","vendor":"codepeople","versions":[{"lessThanOrEqual":"1.5.97","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Zackary Loevseth"}],"descriptions":[{"lang":"en","value":"The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer in all versions up to, and including, 1.5.97 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the 'list_readmore_numberofwords' Other Parameters setting to be configured with a positive integer value; the default value of 0 bypasses the decode-and-truncate branch entirely and is not exploitable through this sink."}],"metrics":[{"cvssV3_1":{"baseScore":7.2,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-79","description":"CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-01T08:28:42.513Z","orgId":"b15e7b5b-3da4-40ae-a43c-f7aa60e62599","shortName":"Wordfence"},"references":[{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3044e60f-b930-42db-ba5d-656e71b84226?source=cve"},{"url":"https://plugins.trac.wordpress.org/browser/appointment-hour-booking/tags/1.5.97/mv/js/jquery.calendar.js"},{"url":"https://plugins.trac.wordpress.org/browser/appointment-hour-booking/tags/1.5.97/cp-main-class.inc.php#L1473"},{"url":"https://plugins.trac.wordpress.org/browser/appointment-hour-booking/tags/1.5.97/cp-main-class.inc.php#L1609"},{"url":"https://plugins.trac.wordpress.org/browser/appointment-hour-booking/tags/1.5.97/cp-main-class.inc.php#L1745"},{"url":"https://plugins.trac.wordpress.org/browser/appointment-hour-booking/tags/1.5.97/classes/cp-base-class.inc.php#L81"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3718725%40appointment-hour-booking&new=3718725%40appointment-hour-booking"}],"timeline":[{"lang":"en","time":"2026-09-23T13:43:40.000Z","value":"Vendor Notified"},{"lang":"en","time":"2026-09-30T20:09:56.000Z","value":"Disclosed"}],"title":"Appointment Hour Booking <= 1.5.97 - Unauthenticated Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer"}},"cveMetadata":{"assignerOrgId":"b15e7b5b-3da4-40ae-a43c-f7aa60e62599","assignerShortName":"Wordfence","cveId":"CVE-2026-96573","datePublished":"2026-10-01T08:28:42.513Z","dateReserved":"2026-09-23T13:27:20.103Z","dateUpdated":"2026-10-01T14:13:25.726Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-01 09:17:10","lastModifiedDate":"2026-10-01 15:17:37","problem_types":["CWE-79","CWE-79 CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-01T14:13:16.706277Z","id":"CVE-2026-96573","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"96573","Ordinal":"1","Title":"Appointment Hour Booking <= 1.5.97 - Unauthenticated Stored DOM-","CVE":"CVE-2026-96573","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"96573","Ordinal":"1","NoteData":"The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer in all versions up to, and including, 1.5.97 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the 'list_readmore_numberofwords' Other Parameters setting to be configured with a positive integer value; the default value of 0 bypasses the decode-and-truncate branch entirely and is not exploitable through this sink.","Type":"Description","Title":"Appointment Hour Booking <= 1.5.97 - Unauthenticated Stored DOM-"}]}}}