CPE
The Appointment Hour Booking plugin for WordPress is vulnerable to Stored DOM-based XSS via the Schedule Calendar List Renderer due to insufficient input sanitization, allowing unauthenticated attackers to execute arbitrary scripts.