SQL Injection Vulnerability in Gravity Bookings Premium Plugin for WordPress
CVE-2026-1719
7.5HIGH
What is CVE-2026-1719?
The Gravity Bookings Premium plugin for WordPress is at risk due to a vulnerability that allows SQL Injection attacks. Insufficient escaping of user-supplied parameters and inadequate preparation of SQL queries enable unauthenticated attackers to inject malicious SQL statements. This can lead to the unauthorized retrieval of sensitive information from the database, posing a significant risk to site security.
Affected Version(s)
Gravity Bookings 0 <= 2.5.9