<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:codepeople:appointment_hour_booking:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3acodepeopleappointment_hour_bookingwordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 10:40:22 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3acodepeopleappointment_hour_bookingwordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored DOM-Based XSS in Appointment Hour Booking Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2026-96573/</link><pubDate>Thu, 01 Oct 2026 10:40:22 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2026-96573/</guid><description>The Appointment Hour Booking plugin for WordPress is vulnerable to Stored DOM-based XSS via the Schedule Calendar List Renderer due to insufficient input sanitization, allowing unauthenticated attackers to execute arbitrary scripts.</description><content:encoded><![CDATA[<p>The Appointment Hour Booking - Booking Calendar plugin for WordPress is affected by a stored DOM-based Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-96573, which impacts all versions up to and including 1.5.97. The flaw originates from improper input sanitization and output escaping within the Schedule Calendar List Renderer.</p>
<p>Attackers can trigger this vulnerability when the 'list_readmore_numberofwords' setting is configured with a positive integer. When this condition is met, the application performs unsanitized rendering of user-supplied data in the browser, enabling the injection and execution of malicious web scripts. Because the vulnerability allows unauthenticated access to the injection sink, an attacker can influence the plugin's configuration or target site administrators and users viewing the compromised booking pages. This vulnerability represents a significant risk for site integrity and user session security within environments using the affected plugin.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to inject arbitrary web scripts into pages rendered by the WordPress plugin. This can lead to unauthorized actions performed on behalf of authenticated users, session hijacking, or the defacement of the affected WordPress site. The vulnerability affects any site using versions of the Appointment Hour Booking plugin through 1.5.97 where the 'list_readmore_numberofwords' setting is enabled with a value greater than zero.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Update the Appointment Hour Booking plugin to a version released after 1.5.97 that addresses CVE-2026-96573.</li>
<li>Review WordPress plugin configurations to audit the 'list_readmore_numberofwords' setting; set to 0 as a temporary mitigation if patching is not immediately feasible.</li>
<li>Inspect web server logs for HTTP requests targeting the booking form parameters that contain script tags or suspicious JavaScript payload patterns.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>xss</category><category>wordpress</category></item></channel></rss>