CVE-2026-16282
Received Received - Intake

Unauthenticated Price Manipulation in Appointment Hour Booking WordPress Plugin

Vulnerability report for CVE-2026-16282, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-08

Last updated on: 2026-08-08

Assigner: WPScan

Description

The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured service price, allowing unauthenticated users to submit an arbitrary final price (including zero or negative) that is stored as the authoritative booking price, corrupting booking and payment records.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-08
Last Modified
2026-08-08
Generated
2026-08-08
AI Q&A
2026-08-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpbooking appointment_hour_booking to 1.5.88 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in the Appointment Hour Booking WordPress plugin before version 1.5.88 allows unauthenticated users to submit an arbitrary booking price via the 'tcost' parameter. The plugin fails to validate this input against the server-side configured service price, enabling manipulation of the final price to zero or negative values. This corrupts booking and payment records by storing the manipulated price as the authoritative value.

Detection Guidance

Check if the Appointment Hour Booking plugin version is below 1.5.88 by inspecting the plugin files or WordPress admin panel. Monitor network traffic for requests containing the 'tcost' parameter with manipulated values.

Impact Analysis

This vulnerability can lead to financial losses by allowing unauthorized users to set booking prices to zero or negative values, disrupting revenue calculations. It also corrupts booking and payment records, causing inaccuracies in transaction histories and potential disputes with clients. Additionally, it may enable unauthorized access to bookings without proper authentication.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA by allowing unauthorized price manipulation in booking and payment records. Corrupted financial data may violate integrity requirements for audit trails and financial reporting under these regulations.

Mitigation Strategies

Update the Appointment Hour Booking plugin to version 1.5.88 or later immediately. If updating is not possible, disable the plugin until the update is applied to prevent price manipulation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16282. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart