SQL Injection Vulnerability in Online Scheduling and Appointment Booking System Plugin for WordPress
CVE-2026-13395
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 30 July 2026
Badges
What is CVE-2026-13395?
The Online Scheduling and Appointment Booking System plugin for WordPress prior to version 27.8 is vulnerable to SQL injection. This flaw arises from the plugin's failure to properly sanitize or cast user-supplied parameters in unauthenticated front-end booking requests. Attackers can exploit this vulnerability to execute malicious SQL queries, leading to unauthorized access to sensitive information, including password hashes stored in the database. It is crucial for site administrators to update their plugins promptly to safeguard against potential exploitation.
Affected Version(s)
Online Scheduling and Appointment Booking System 0 < 27.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.