cleantalk
Vulnerabilities and Security Researches

BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin, CVE-2025-31910

CVE, Research URL

CVE-2025-31910

Published on
Apr 01, 2025
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reputeinfosystems BookingPress bookingpress-appointment-booking allows SQL Injection.This issue affects BookingPress: from n/a through <= 1.1.28.
Affected versions
max 1.1.28.
Status
vulnerable