Skip to content
Threat Feed
high advisory

Stored DOM-Based XSS in Appointment Hour Booking Plugin

The Appointment Hour Booking plugin for WordPress is vulnerable to Stored DOM-based XSS via the Schedule Calendar List Renderer due to insufficient input sanitization, allowing unauthenticated attackers to execute arbitrary scripts.

CVE search metadata

CVE search record: CVE-2026-96573. Severity: high. CVSS: 7.2. KEV: no. Product: Appointment Hour Booking – Booking Calendar (<= 1.5.97). Brief: Stored DOM-Based XSS in Appointment Hour Booking Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-96573/

The Appointment Hour Booking - Booking Calendar plugin for WordPress is affected by a stored DOM-based Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-96573, which impacts all versions up to and including 1.5.97. The flaw originates from improper input sanitization and output escaping within the Schedule Calendar List Renderer.

Attackers can trigger this vulnerability when the 'list_readmore_numberofwords' setting is configured with a positive integer. When this condition is met, the application performs unsanitized rendering of user-supplied data in the browser, enabling the injection and execution of malicious web scripts. Because the vulnerability allows unauthenticated access to the injection sink, an attacker can influence the plugin's configuration or target site administrators and users viewing the compromised booking pages. This vulnerability represents a significant risk for site integrity and user session security within environments using the affected plugin.

Impact

Successful exploitation allows unauthenticated attackers to inject arbitrary web scripts into pages rendered by the WordPress plugin. This can lead to unauthorized actions performed on behalf of authenticated users, session hijacking, or the defacement of the affected WordPress site. The vulnerability affects any site using versions of the Appointment Hour Booking plugin through 1.5.97 where the 'list_readmore_numberofwords' setting is enabled with a value greater than zero.

Recommendation

Prioritized actions for security teams:

  • Update the Appointment Hour Booking plugin to a version released after 1.5.97 that addresses CVE-2026-96573.
  • Review WordPress plugin configurations to audit the 'list_readmore_numberofwords' setting; set to 0 as a temporary mitigation if patching is not immediately feasible.
  • Inspect web server logs for HTTP requests targeting the booking form parameters that contain script tags or suspicious JavaScript payload patterns.

Immediate actions

Update Appointment Hour Booking to the latest version

IT Operations 48h

Mitigations

Set 'list_readmore_numberofwords' to 0

immediate IT Operations

CVE-2026-96573