CVE WATCH / VULNERABILITY DETAIL
CVE-2026-96573
HIGHCVSS 7.2NVD feed
Published 1 October 2026 · tracked since 1 October 2026
Description
The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer in all versions up to, and including, 1.5.97 due to insufficient input sanitization and output escaping.
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-97661 HIGH 7.2
- CVE-2026-92244 HIGH 7.2
- CVE-2026-95687 HIGH 8.8
- CVE-2026-96268 MEDIUM 6.4
- CVE-2026-96813 HIGH 7.2
- CVE-2026-15983 HIGH 8.1
- CVE-2026-85235 HIGH 7.2
- CVE-2026-89424 MEDIUM 6.4
- CVE-2026-90992 MEDIUM 6.4
- CVE-2026-14995 HIGH 7.2