WP Booking Calendar, 6689d124309d6527b52d145b54cb612bb080eec4
- CVE, Research URL
- Home page URL
- Application
- Published on
- Jul 14, 2016
- Research Description
- Booking Calendar [booking] < 6.2.1 WordPress Booking Calendar Plugin 6.2 - SQL Injection Booking Calendar Plugin before 6.2 is prone to a SQL Injection vulnerability. The parameters are not sanitized properly in the wpdev_get_args_from_request_in_bk_listing() function from booking/lib/wpdev-bk-lib.php (line 709). It allows remote attackers to view data from the database by luring the target user into a malicious website. Update Booking Calendar Plugin to 6.2.1.
- Affected versions
-
max 6.2.1.
- Status
-
vulnerable