Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0.
Published: 2026-10-05
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: SQL Injection
Action: Immediate Patch
AI Analysis

Impact

The WP BASE Booking plugin for WordPress contains an improper neutralization of input that allows an attacker to inject arbitrary SQL commands into the database. This flaw enables blind SQL injection against the plugin’s backend, potentially granting the attacker unauthorized data access, manipulation, or disruption of booking records. The vulnerability falls under CWE‑89 and is rated high severity.

Affected Systems

Affected systems are WordPress sites that have the WP BASE Booking plugin installed, from any pre‑6.5.0 release up to and including 6.4.0. The warning applies to all instances of the plugin regardless of site configuration, as the vulnerable code is present throughout the entire plugin set up to that version.

Risk and Exploitability

Risk is significant with a CVSS score of 8.5, indicating high impact and exploitability. The EPSS score is not available, but the vulnerability is not currently listed in the CISA KEV catalog. The attack vector is inferred to be remote, through crafted HTTP requests to the plugin’s publicly accessible endpoints, and would require only blind assessment to reveal success. No known public exploits have been reported at the time of this analysis.

Generated by OpenCVE AI on October 5, 2026 at 20:22 UTC.

Remediation

Vendor Solution

Update the WordPress WP BASE Booking plugin to the latest available version (at least 6.5.0).


OpenCVE Recommended Actions

  • Upgrade WP BASE Booking to a version newer than 6.4.0, minimum 6.5.0.
  • Enforce strict input validation on all booking form fields to mitigate any remaining injection vectors.
  • Apply the latest WordPress core security updates and keep all plugins updated.
  • Enable logging for database queries and review logs for suspicious patterns.

Generated by OpenCVE AI on October 5, 2026 at 20:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0.
Title WordPress WP BASE Booking plugin <= 6.4.0 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-05T19:00:11.467Z

Reserved: 2026-09-30T00:15:58.644Z

Link: CVE-2026-103066

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T20:17:08.027

Modified: 2026-10-05T20:17:08.027

Link: CVE-2026-103066

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T20:30:22Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')