SQL Injection Vulnerability in Booking Calendar Plugin from WpDevArt
CVE-2024-10856
What is CVE-2024-10856?
The Booking Calendar plugin by WpDevArt is exposed to a significant security flaw characterized by a time-based, blind SQL injection. This vulnerability is triggered through an inadequate escape mechanism on the 'id' parameter in the 'wpdevart_booking_calendar' shortcode, specifically in versions up to and including 3.2.19. For exploitation to occur, a specific theme option known as 'delete_prev_date' must be enabled, thus facilitating an environment for authenticated attackers with contributor-level access or higher to inject additional SQL queries. These queries can potentially access sensitive data such as passwords from the database, putting user data at risk and compromising the overall integrity of the site.
Affected Version(s)
Booking calendar, Appointment Booking System * <= 3.2.19