CVE-2026-103352: WordPress WP BASE Booking plugin <= 6.4.0 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wp-base-booking-of-appointments-services-and-eventsto a version that resolves this vulnerability.Fixed in 6.5.0
Event History
Frequently Asked Questions
Who can exploit this issue?
The CVSS vector indicates that it can be exploited remotely over the network without privileges or user interaction. An attacker would only need access to a reachable instance using an affected version of the plugin.
Which versions are affected?
WP BASE Booking versions through 6.4.0 are affected. The provided data does not identify a fixed version.
What is the potential impact?
The issue allows blind SQL injection and is rated critical with a 9.3 CVSS score. The vector indicates high confidentiality impact, no integrity impact, and low availability impact, with scope changed.