SQL Injection Vulnerability in WP BASE Booking by WordPress
CVE-2026-103066
8.5HIGH
What is CVE-2026-103066?
The WP BASE Booking plugin for WordPress is susceptible to a SQL Injection vulnerability due to improper neutralization of special elements utilized in SQL commands. This lets an attacker execute blind SQL injection attacks, potentially leading to unauthorized data exposure. Versions ranging from n/a through 6.4.0 are affected, highlighting the importance of updating to secure releases and implementing best practices to protect against such vulnerabilities.
Affected Version(s)
WP BASE Booking 0 <= 6.4.0