CVE-2022-4034
MEDIUMAppointment Hour Booking Plugin <1.3.72 - Code Injection
Title source: llmDescription
The Appointment Hour Booking Plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3.72. This makes it possible for unauthenticated attackers to embed untrusted input into content during booking creation that may be exported as a CSV file when a site's administrator exports booking details. This can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
References (3)
Scores
CVSS v3
5.8
EPSS
0.0486
EPSS Percentile
89.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1236
Status
published
Products (2)
codepeople/Appointment Hour Booking – Booking Calendar
< 1.3.72
dwbooster/appointment_hour_booking
< 1.3.72
Published
Nov 29, 2022
Tracked Since
Feb 18, 2026