First published: Thu Aug 22 2019(Updated: )
The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CodePeople Appointment Hour Booking | <1.1.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10916 has a medium severity rating due to the potential for SQL injection leading to unauthorized database access.
To fix CVE-2016-10916, upgrade the appointment-booking-calendar plugin to version 1.1.24 or later.
CVE-2016-10916 is classified as an SQL injection vulnerability.
CVE-2016-10916 affects all versions of the appointment-booking-calendar plugin prior to 1.1.24.
CVE-2016-10916 can allow attackers to manipulate SQL queries, potentially exposing sensitive data or allowing full control over the database.