SQL Injection Vulnerability in Booking Calendar by wpdevelop
CVE-2026-32358
7.6HIGH
What is CVE-2026-32358?
The Booking Calendar plugin by wpdevelop is susceptible to a Blind SQL Injection vulnerability due to improper handling of special elements in SQL commands. This flaw allows attackers to execute arbitrary SQL queries, potentially compromising the database. Users of the affected versions, from n/a to 10.14.15, are urged to update their plugins immediately to mitigate the risks associated with this vulnerability.
Affected Version(s)
Booking Calendar 0 <= 10.14.15