What is CVE-2026-16282?
This vulnerability affects the Appointment Hour Booking WordPress plugin before version 1.5.88, allowing unauthenticated users to submit an arbitrary booking price (including zero or negative) that bypasses server-side service price validation. The manipulated price is then stored as the authoritative booking value, potentially leading to financial loss. Immediate update to version 1.5.88 or later is required.
Azərbaycanca: Bu zəiflik Appointment Hour Booking WordPress plugin-inin 1.5.88-dən əvvəlki versiyalarına təsir edir və autentifikasiya olunmamış istifadəçilərə sifariş zamanı qiyməti serverdə təyin olunmuş rəsmi xidmət qiyməti ilə müqayisədə özbaşına (sıfır və ya mənfi daxil olmaqla) dəyişməyə imkan verir. Nəticədə, bu saxta qiymət rəsmi sifariş dəyəri kimi bazada saxlanıla bilər. Plugin-i dərhal 1.5.88 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: WordPress
FAQ2
Which versions of the Appointment Hour Booking plugin are affected by CVE-2026-16282?
The vulnerability affects the Appointment Hour Booking WordPress plugin before version 1.5.88.
What can an unauthenticated user do by exploiting CVE-2026-16282?
They can bypass server-side service price validation and submit an arbitrary booking price, including zero or negative values.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.