SQL Injection Vulnerability in Directorist Booking from Directorist
CVE-2026-22336

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 April 2026

What is CVE-2026-22336?

A vulnerability exists in the Directorist Booking plugin that allows for improper neutralization of special elements used in SQL commands, leading to SQL Injection attacks. This flaw affects versions of Directorist Booking prior to 3.0.2, enabling unauthorized access to the database, which may allow attackers to manipulate or retrieve sensitive information. Organizations using the affected plugin should prioritize updates and implement security measures to mitigate the risk of exploitation.

Affected Version(s)

Directorist Booking < 3.0.2

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xd4rk5id3 | Patchstack Bug Bounty Program
.