Impact
The appointment‑hour‑booking WordPress plugin is vulnerable to stored DOM‑based XSS through the Booking Form Single‑Line Field in the Schedule Calendar List Renderer. Unsanitized input is decoded and escaped only when the ‘list_readmore_numberofwords’ setting is configured to a positive integer, enabling an unauthenticated attacker to inject arbitrary JavaScript that will run in the browser when a page containing the infected booking list is viewed. This permits the attacker to hijack sessions, deface content, or perform phishing attacks without needing administrative credentials.
Affected Systems
The vulnerability affects the WordPress plugin codepeople:Appointment Hour Booking – Booking Calendar in all releases up to and including version 1.5.97. Any WordPress installation using the affected plugin without a patch is susceptible.
Risk and Exploitability
The CVSS base score is 7.2, indicating a high impact level. No EPSS score is available, and the flaw is not yet listed in CISA’s KEV catalogue, suggesting that exploitation may not be widespread yet, but the lack of input validation means the flaw can be abused at the attacker’s discretion once disclosed. Attackers would need to ensure the configuration parameter is set to a positive integer to reach the vulnerable code path; the default setting of zero provides a brief but partial safeguard.
OpenCVE Enrichment