CVE-2026-32466: WordPress Gravity Forms Bookings premium plugin <= 2.1 - SQL Injection vulnerability
Published Aug 18, 2026
·Updated
Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.
Affected Software
1 affected component
WordPress Gravity Forms Bookings premium<=2.1
Event History
Aug 18, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed?
Sites using WordPress Gravity Forms Bookings premium version 2.1 or earlier are affected. The issue is reachable over the network and does not require user interaction.
2
What level of access does an attacker need?
An attacker needs Subscriber-level privileges to exploit the vulnerability. No additional conditions are provided in the available data.
3
Does this affect the default configuration?
The affected component is identified as the premium edition of Gravity Forms Bookings. The available data does not state whether a default installation or configuration is affected.