Unauthenticated SQL Injection in BookingPress Appointment Booking Pro by BookingPress
CVE-2026-68566

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 August 2026

What is CVE-2026-68566?

An unauthenticated SQL injection vulnerability has been identified in versions of BookingPress Appointment Booking Pro up to 6.0.2. This weakness allows attackers to execute arbitrary SQL queries without authentication. By exploiting this flaw, malicious actors could access sensitive data, manipulate databases, or disrupt application functionality. It is imperative for users to promptly update to the latest version to mitigate potential security threats.

Affected Version(s)

BookingPress Appointment Booking Pro <= 6.0.2

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

dutafi | Patchstack Bug Bounty Program
.