CVE-2026-103066: WordPress WP BASE Booking plugin <= 6.4.0 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wp-base-booking-of-appointments-services-and-eventsto a version that resolves this vulnerability.Fixed in 6.5.0
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability requires low-level privileges (PR:L). It can be exploited remotely without user interaction (AV:N, UI:N).
Is there evidence that a default installation is affected?
The available data identifies affected versions through 6.4.0, but it does not state whether the vulnerable functionality is enabled or reachable in the plugin's default configuration.
What are the potential consequences of successful exploitation?
Successful blind SQL injection could expose highly sensitive information, reflected by the high confidentiality impact (C:H). The integrity impact is listed as none, while availability impact is low (I:N, A:L).
How can I determine whether my site is affected?
Check whether WP BASE Booking is installed and determine its installed version. Versions up to and including 6.4.0 are identified as affected.