WordPress Booking calendar, Appointment Booking System Plugin <= 3.2.7 is vulnerable to SQL Injection
CVE-2022-47428

9.8CRITICAL

Key Information:

Vendor
WordPress
Vendor
CVE Published:
6 November 2023

Summary

The WpDevArt Booking Calendar and Appointment Booking System are susceptible to an SQL Injection vulnerability due to improper neutralization of special elements within SQL commands. This vulnerability allows attackers to manipulate SQL queries, potentially exposing sensitive database information. Users of affected versions, including 3.2.7 and earlier, are encouraged to implement the necessary security measures to safeguard their systems against this exploit.

Affected Version(s)

Booking calendar, Appointment Booking System <= 3.2.7

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

thiennv (Patchstack Alliance)
.