CVE-2023-50840: WordPress Booking Manager Plugin <= 2.1.5 is vulnerable to SQL Injection
Published Dec 28, 2023
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevelop, oplugins Booking Manager.This issue affects Booking Manager: from n/a through 2.1.5.
Affected Software
1 affected component
oplugins Booking Manager Wordpress<=2.1.5
Remediation
Information
Update to 2.1.6 or a higher version.
Event History
Dec 28, 2023
CVE Published
via MITRE·06:54 PM
Data Sourced
via MITRE·06:54 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-50840?
CVE-2023-50840 has been assessed as a high severity SQL injection vulnerability.
2
How do I fix CVE-2023-50840?
To fix CVE-2023-50840, update the Oplugins Booking Manager to the latest version beyond 2.1.5.
3
What versions are affected by CVE-2023-50840?
CVE-2023-50840 affects Oplugins Booking Manager from n/a through version 2.1.5.
4
What type of vulnerability is CVE-2023-50840?
CVE-2023-50840 is categorized as an SQL Injection vulnerability.
5
Can CVE-2023-50840 lead to data leaks?
Yes, exploiting CVE-2023-50840 could potentially lead to unauthorized access to database contents.