Impact
The WP BASE Booking plugin for WordPress contains an improper neutralization of input that allows an attacker to inject arbitrary SQL commands into the database. This flaw enables blind SQL injection against the plugin’s backend, potentially granting the attacker unauthorized data access, manipulation, or disruption of booking records. The vulnerability falls under CWE‑89 and is rated high severity.
Affected Systems
Affected systems are WordPress sites that have the WP BASE Booking plugin installed, from any pre‑6.5.0 release up to and including 6.4.0. The warning applies to all instances of the plugin regardless of site configuration, as the vulnerable code is present throughout the entire plugin set up to that version.
Risk and Exploitability
Risk is significant with a CVSS score of 8.5, indicating high impact and exploitability. The EPSS score is not available, but the vulnerability is not currently listed in the CISA KEV catalog. The attack vector is inferred to be remote, through crafted HTTP requests to the plugin’s publicly accessible endpoints, and would require only blind assessment to reveal success. No known public exploits have been reported at the time of this analysis.
OpenCVE Enrichment