Medium severity4.8NVD Advisory· Published Jun 13, 2022· Updated Jun 17, 2026
CVE-2022-1710
CVE-2022-1710
Description
The Appointment Hour Booking WordPress plugin before 1.3.56 does not sanitise and escape a settings of its Calendar fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<1.3.56+ 1 more
- (no CPE)range: <1.3.56
- (no CPE)
- cpe:2.3:a:dwbooster:appointment_hour_booking:*:*:*:*:*:wordpress:*:*Range: <1.3.56
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/ed162ccc-88e6-41e8-b24d-1b9f77a038b6nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.