QID 731150
Date Published: 2024-02-14
QID 731150: WordPress Booking Plugin SQL Injection Vulnerability
Plugin provides an easy-to-use booking system for displaying calendar availability receive bookings from your website visitors and manage bookings through a modern and clean booking admin panel.
CVE-2024-1207 : The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the calendar_request_params[dates_ddmmyy_csv parameter in all versions up to and including 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
Affected Versions:
WordPress Booking plugin versions prior to 9.9.1
QID Detection Logic:
This unauthenticated detection checks for installed vulnerable version for Booking Plugin using Blind Elephant Fingerprint technique.
Successful exploitation of this vulnerability may allow unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
- WordPress Booking Plugin Release Notes -
wordpress.org/plugins/booking/#developers
CVEs related to QID 731150
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Booking plugin |
|