Medium 4.4
2026-01-28< 1.5.61
Appointment Hour Booking – Booking Calendar <= 1.5.60 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Min/Max Length' Field Configuration
Minimum safe version
1.5.61
Update to 1.5.61 or later to address 14 fixable vulnerabilities
Appointment Hour Booking – Booking Calendar <= 1.5.60 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Min/Max Length' Field Configuration
CVE-2024-32720
CVE-2023-45649
WordPress Appointment Hour Booking Plugin <= 1.3.72 is vulnerable to Other Vulnerability Type
WordPress Appointment Hour Booking Plugin <= 1.3.72 is vulnerable to CSV Injection
WordPress Appointment Hour Booking Plugin <= 1.3.72 is vulnerable to Bypass Vulnerability
CVE-2022-4036
CVE-2022-4035
CVE-2022-4034
CVE-2022-41692
CVE-2022-1710
WordPress Appointment Hour Booking plugin <= 1.1.45 - Stored Cross-Site Scripting (XSS) vulnerability
CVE-2021-24673
CVE-2021-24712