SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-65514

MEDIUM · CVSS 6.5 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The Appointment Hour Booking plugin versions up to 1.5.86 are vulnerable to a Contributor Cross Site Scripting (XSS) flaw, which could allow attackers to inject malicious scripts into web pages viewed by other users. This vulnerability poses a medium risk, as it can lead to unauthorized actions or data exposure for users with contributor-level access. Organizations using this plugin should prioritize patching or upgrading to mitigate potential exploitation risks.

CVE
CVE-2026-65514
Severity
MEDIUM
CVSS
6.5
EPSS
0.16%

Original NVD Description

Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.