SQL Injection Vulnerability in WP BASE Booking by WordPress
CVE-2026-103352

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 October 2026

What is CVE-2026-103352?

The WP BASE Booking plugin for WordPress contains a vulnerability that allows attackers to perform Blind SQL Injection. This issue arises due to improper neutralization of special elements used in SQL commands, potentially allowing unauthorized data access. The vulnerability affects versions of WP BASE Booking up to 6.4.0, posing significant risks to vulnerable implementations.

Affected Version(s)

WP BASE Booking 0 <= 6.4.0

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Khanh Nguyen | Patchstack Bug Bounty Program
.