CVE-2022-0739: BookingPress < 1.0.11 - Unauthenticated SQL Injection
The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query via the bookingpressfrontgetcategoryservices AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-0739?
The severity of CVE-2022-0739 is classified as critical with a severity value of 9.8.
How does CVE-2022-0739 affect the BookingPress WordPress plugin?
CVE-2022-0739 affects the BookingPress WordPress plugin before version 1.0.11.
What is the vulnerability type of CVE-2022-0739?
The vulnerability type of CVE-2022-0739 is unauthenticated SQL Injection.
How can I fix CVE-2022-0739?
To fix CVE-2022-0739, update the BookingPress WordPress plugin to version 1.0.11 or later.
Where can I find more information about CVE-2022-0739?
More information about CVE-2022-0739 can be found at the following references: [link 1](https://plugins.trac.wordpress.org/changeset/2684789), [link 2](https://wpscan.com/vulnerability/388cd42d-b61a-42a4-8604-99b812db2357).