Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 11 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 | |
| Metrics |
cvssV3_1
|
Sat, 08 Aug 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured service price, allowing unauthenticated users to submit an arbitrary final price (including zero or negative) that is stored as the authoritative booking price, corrupting booking and payment records. | |
| Title | Appointment Hour Booking < 1.5.88 - Unauthenticated Booking Price Manipulation via tcost Parameter | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-11T19:34:02.056Z
Reserved: 2026-07-20T10:58:19.374Z
Link: CVE-2026-16282
Updated: 2026-08-11T19:33:52.645Z
Status : Received
Published: 2026-08-08T07:17:09.900
Modified: 2026-08-11T20:17:28.180
Link: CVE-2026-16282
No data.
OpenCVE Enrichment
Updated: 2026-08-13T09:30:07Z
No weakness.