Impact
The WP Booking System – Booking Calendar plugin suffers from a time‑based SQL injection in the 'current_month' parameter. Because this parameter is improperly escaped and the surrounding query lacks proper preparation, an attacker with authenticated Subscriber‑level access can inject arbitrary SQL. This injection allows the attacker to execute additional statements that read or modify sensitive data in the database, potentially exposing personal or booking information. The weakness exists in all releases up to and including 2.1.0.1.
Affected Systems
The plugin, produced by murgroland, is used in WordPress installations. Any site running WP Booking System – Booking Calendar version 2.1.0.1 or older is vulnerable to this authentication‑based SQL injection.
Risk and Exploitability
With a CVSS base score of 6.5 the risk is moderate. The EPSS score is not available, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. The likely attack vector is an authenticated user, such as a Subscriber or higher, sending a crafted request containing a malicious 'current_month' value to the Ajax endpoint that processes the calendar. No additional network exploitation prerequisites are specified beyond valid authentication.
OpenCVE Enrichment