cleantalk
Vulnerabilities and Security Researches

WP Booking Calendar, 6689d124309d6527b52d145b54cb612bb080eec4

Application

WP Booking Calendar

Published on
Jul 14, 2016
Research Description
Booking Calendar [booking] < 6.2.1 WordPress Booking Calendar Plugin 6.2 - SQL Injection Booking Calendar Plugin before 6.2 is prone to a SQL Injection vulnerability. The parameters are not sanitized properly in the wpdev_get_args_from_request_in_bk_listing() function from booking/lib/wpdev-bk-lib.php (line 709). It allows remote attackers to view data from the database by luring the target user into a malicious website. Update Booking Calendar Plugin to 6.2.1.
Affected versions
max 6.2.1.
Status
vulnerable