QID 731150

Date Published: 2024-02-14

QID 731150: WordPress Booking Plugin SQL Injection Vulnerability

Plugin provides an easy-to-use booking system for displaying calendar availability receive bookings from your website visitors and manage bookings through a modern and clean booking admin panel.

CVE-2024-1207 : The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the calendar_request_params[dates_ddmmyy_csv parameter in all versions up to and including 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Affected Versions:
WordPress Booking plugin versions prior to 9.9.1

QID Detection Logic:
This unauthenticated detection checks for installed vulnerable version for Booking Plugin using Blind Elephant Fingerprint technique.

Successful exploitation of this vulnerability may allow unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to upgrade to WP Booking version 9.9.1 and later to remediate this vulnerability.
    Vendor References

    CVEs related to QID 731150

    Software Advisories
    Advisory ID Software Component Link
    Booking plugin URL Logo wordpress.org/plugins/booking/#developers