SQL Injection Vulnerability in Gravity Forms Bookings Plugin by Rocketgenius
CVE-2026-32466
8.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 August 2026
What is CVE-2026-32466?
A SQL injection vulnerability exists in the Gravity Forms Bookings premium plugin, impacting versions 2.1 and earlier. This issue could allow an attacker to manipulate database queries through specially crafted input, potentially exposing sensitive data or performing unauthorized operations on the database. Users of the affected plugin are encouraged to update to the latest version to mitigate these security risks.
Affected Version(s)
Gravity Forms Bookings premium <= 2.1