Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp FAT Services Booking fat-services-booking allows SQL Injection.This issue affects FAT Services Booking: from n/a through <= 5.6.
Published: 2025-05-19
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an SQL Injection flaw in the FAT Services Booking WordPress plugin caused by improper handling of special elements in SQL commands (CWE‑89). This weakness allows a malicious actor to inject arbitrary SQL statements through user‑supplied input. The CVE description confirms that such injection is possible, but it does not explicitly state what the attacker can read, modify, or delete; that outcome is inferred from the nature of SQL Injection and the typical privileges of the WordPress database user.

Affected Systems

The flaw exists in the roninwp FAT Services Booking plugin for WordPress versions up to and including 5.6. Any site using plugin version 5.6 or older is potentially vulnerable.

Risk and Exploitability

The CVSS v3 score of 8.5 classifies the issue as high severity. The EPSS score of < 1 % indicates a low current likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is client‑side, via unauthenticated HTTP requests to the plugin’s database‑access endpoints; this is inferred because the description does not mention authentication requirements. Successful exploitation could enable arbitrary SQL execution against the WordPress database, potentially compromising confidentiality, integrity, or availability of stored data.

Generated by OpenCVE AI on May 2, 2026 at 01:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the FAT Services Booking plugin to the latest version released by roninwp (>= 5.7).
  • If an upgrade is not immediately possible, deactivate or remove the plugin entirely to eliminate the vulnerable code.
  • Restrict access to all booking‑related endpoints so that only authenticated administrators can reach them, and enforce HTTPS on the site to protect data in transit.

Generated by OpenCVE AI on May 2, 2026 at 01:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-15780 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp FAT Services Booking allows SQL Injection.This issue affects FAT Services Booking: from n/a through 5.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp FAT Services Booking allows SQL Injection.This issue affects FAT Services Booking: from n/a through 5.6. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp FAT Services Booking fat-services-booking allows SQL Injection.This issue affects FAT Services Booking: from n/a through <= 5.6.
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Mon, 19 May 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 19 May 2025 20:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp FAT Services Booking allows SQL Injection.This issue affects FAT Services Booking: from n/a through 5.6.
Title WordPress FAT Services Booking plugin <= 5.6 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Roninwp Fat Services Booking
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:29.346Z

Reserved: 2025-04-16T06:22:10.075Z

Link: CVE-2025-39355

cve-icon Vulnrichment

Updated: 2025-05-19T21:11:38.432Z

cve-icon NVD

Status : Deferred

Published: 2025-05-19T20:15:23.490

Modified: 2026-04-23T15:29:24.053

Link: CVE-2025-39355

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T01:45:26Z

Weaknesses