CVE-2016-10916: SQL Injection
Published Aug 22, 2019
·Updated
The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.
Affected Software
1 affected component
CodePeople Appointment Booking Calendar Wordpress<1.1.24
Event History
Aug 22, 2019
CVE Published
via MITRE·12:11 PM
Data Sourced
via MITRE·12:11 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10916?
CVE-2016-10916 has a medium severity rating due to the potential for SQL injection leading to unauthorized database access.
2
How do I fix CVE-2016-10916?
To fix CVE-2016-10916, upgrade the appointment-booking-calendar plugin to version 1.1.24 or later.
3
What type of vulnerability is CVE-2016-10916?
CVE-2016-10916 is classified as an SQL injection vulnerability.
4
Which versions of the appointment-booking-calendar plugin are affected by CVE-2016-10916?
CVE-2016-10916 affects all versions of the appointment-booking-calendar plugin prior to 1.1.24.
5
What impact can CVE-2016-10916 have on my WordPress site?
CVE-2016-10916 can allow attackers to manipulate SQL queries, potentially exposing sensitive data or allowing full control over the database.