First published: Mon Mar 18 2019(Updated: )
SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Booking Calendar | =8.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20556 is rated as a critical vulnerability due to the potential for remote attackers to execute arbitrary SQL commands.
To fix CVE-2018-20556, update the Booking Calendar plugin to the latest version that addresses this SQL injection vulnerability.
The impact of CVE-2018-20556 on your WordPress site can include unauthorized access to your database and the ability to manipulate or extract sensitive data.
CVE-2018-20556 specifically affects version 8.4.3 of the Booking Calendar plugin for WordPress.
CVE-2018-20556 can be exploited by remote attackers who can manipulate the booking_id parameter in a request to execute SQL commands.