What the vulnerability does
01Description
The Appointment Hour Booking Plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3.72. This makes it possible for unauthenticated attackers to embed untrusted input into content during booking creation that may be exported as a CSV file when a site's administrator exports booking details. This can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
Explanation of Vulnerability in Simple Terms
02Summary
Appointment Hour Booking versions up to 1.3.72 contain a vulnerability that allows an attacker to read or modify limited data on an affected site. The attack requires the victim to visit a malicious link or page, and the attacker has no special privileges. The vulnerability affects the booking calendar component and may impact other parts of the site.
What an attacker can do
03Attacker Capabilities
Read or modify limited data on the site by tricking a visitor into clicking a malicious link.
Potential impact on your site
04Site Impact
Booking data and site information could be exposed or altered if users are tricked into visiting malicious links.
Conditions required to exploit
05Prerequisites
Victim must click a malicious link or visit an attacker-controlled page; no authentication required.
Key dates
06Disclosure timeline
November 29, 2022
CVE published
April 8, 2026
Record updated