4.4
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
Description
The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form field configuration parameters in all versions up to, and including, 1.5.60 due to insufficient input sanitization and output escaping on the 'Min length/characters' and 'Max length/characters' field configuration values. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the form builder interface. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Basic Information
ID
CVE-2026-1083
Source
Wordfence
Published
Jan 28, 2026 at 05:30
Affected Product
Vendor
codepeople
Product
Appointment Hour Booking – Booking Calendar
Version
*
Affected Versions
codepeople Appointment Hour Booking – Booking Calendar *
CWE Classification
References
- www.wordfence.com /threat-intel/vulnerabilities/id/a5cb1fea-134f-4c81-8f2f-76ee42df7f77
- plugins.trac.wordpress.org /browser/appointment-hour-booking/trunk/js/fields-admin/01_fbuilder.ftext.js
- plugins.trac.wordpress.org /browser/appointment-hour-booking/tags/1.5.57/js/fields-admin/01_fbuilder.ftext.js
- plugins.trac.wordpress.org /changeset