SQL Injection Vulnerability in Booking Calendar Plugin from WpDevArt
CVE-2024-10856
What is CVE-2024-10856?
The Booking Calendar plugin by WpDevArt is exposed to a significant security flaw characterized by a time-based, blind SQL injection. This vulnerability is triggered through an inadequate escape mechanism on the 'id' parameter in the 'wpdevart_booking_calendar' shortcode, specifically in versions up to and including 3.2.19. For exploitation to occur, a specific theme option known as 'delete_prev_date' must be enabled, thus facilitating an environment for authenticated attackers with contributor-level access or higher to inject additional SQL queries. These queries can potentially access sensitive data such as passwords from the database, putting user data at risk and compromising the overall integrity of the site.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Booking calendar, Appointment Booking System * <= 3.2.19
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
