The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured service price, allowing unauthenticated users to submit an arbitrary final price (including zero or negative) that is stored as the authoritative booking price, corrupting booking and payment records.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-08 07:17
Updated : 2026-08-26 16:31
NVD link : CVE-2026-16282
Mitre link : CVE-2026-16282
CVE.ORG link : CVE-2026-16282
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication
