
💳 WordPress booking plugin lets users manipulate prices CVE-2026-16282 affects Appointment Hour Booking <1.5.88. The server trusts a client-supplied booking price instead of validating it against the configured price. Unauthenticated users could submit arbitrary values—including zero or negative prices—corrupting booking/payment records. 🔎 Source: Rapid7 / MITRE CVE #WordPress #EcommerceSecurity #CVE #CyberSecurity
Post summary
CVE‑2026‑16282 reveals that Appointment Hour Booking <1.5.88 accepts unauthenticated booking prices, enabling price manipulation and potential record corruption; no PoC, exploit, patch or active exploitation is reported.
