SQL Injection Vulnerability in Directorist Booking from Directorist
CVE-2026-22336
9.3CRITICAL
What is CVE-2026-22336?
A vulnerability exists in the Directorist Booking plugin that allows for improper neutralization of special elements used in SQL commands, leading to SQL Injection attacks. This flaw affects versions of Directorist Booking prior to 3.0.2, enabling unauthorized access to the database, which may allow attackers to manipulate or retrieve sensitive information. Organizations using the affected plugin should prioritize updates and implement security measures to mitigate the risk of exploitation.
Affected Version(s)
Directorist Booking < 3.0.2