CVE-2025-31910: WordPress BookingPress plugin <= 1.1.28 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reputeinfosystems BookingPress bookingpress-appointment-booking allows SQL Injection.This issue affects BookingPress: from n/a through <= 1.1.28.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31910?
CVE-2025-31910 is classified as a medium severity SQL Injection vulnerability that affects certain versions of BookingPress.
How do I fix CVE-2025-31910?
To mitigate CVE-2025-31910, update BookingPress to the latest version beyond 1.1.28 as this patch addresses the SQL Injection issue.
What versions are affected by CVE-2025-31910?
CVE-2025-31910 affects BookingPress versions from n/a through 1.1.28.
What type of vulnerability is CVE-2025-31910?
CVE-2025-31910 is an SQL Injection vulnerability due to improper neutralization of special elements in SQL commands.
Who is the vendor for the product affected by CVE-2025-31910?
The vendor for the affected product in CVE-2025-31910 is Repute Info Systems.