CVE-2022-4034

MEDIUM

Appointment Hour Booking Plugin <1.3.72 - Code Injection

Title source: llm
STIX 2.1

Description

The Appointment Hour Booking Plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3.72. This makes it possible for unauthenticated attackers to embed untrusted input into content during booking creation that may be exported as a CSV file when a site's administrator exports booking details. This can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

Scores

CVSS v3 5.8
EPSS 0.0486
EPSS Percentile 89.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1236
Status published
Products (2)
codepeople/Appointment Hour Booking – Booking Calendar < 1.3.72
dwbooster/appointment_hour_booking < 1.3.72
Published Nov 29, 2022
Tracked Since Feb 18, 2026