SQL Injection Vulnerability in Online Scheduling and Appointment Booking System Plugin for WordPress
CVE-2026-13395

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
30 July 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-13395?

The Online Scheduling and Appointment Booking System plugin for WordPress prior to version 27.8 is vulnerable to SQL injection. This flaw arises from the plugin's failure to properly sanitize or cast user-supplied parameters in unauthenticated front-end booking requests. Attackers can exploit this vulnerability to execute malicious SQL queries, leading to unauthorized access to sensitive information, including password hashes stored in the database. It is crucial for site administrators to update their plugins promptly to safeguard against potential exploitation.

Affected Version(s)

Online Scheduling and Appointment Booking System 0 < 27.8

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jakub Herman
WPScan
.