First published: Fri Apr 04 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shiptrack Booking Calendar and Notification allows Blind SQL Injection.This issue affects Booking Calendar and Notification: from n/a through 4.0.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Booking Calendar and Notification plugin | <=4.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31403 is classified as a critical severity vulnerability due to the potential for Blind SQL Injection.
To fix CVE-2025-31403, update the Booking Calendar and Notification plugin to version 4.0.4 or later.
CVE-2025-31403 affects the Booking Calendar and Notification plugin for WordPress versions up to and including 4.0.3.
CVE-2025-31403 is an SQL Injection vulnerability that allows attackers to manipulate SQL queries.
If exploited, CVE-2025-31403 could allow attackers to access sensitive database information through Blind SQL Injection.