Impact
This SQL injection vulnerability exists when the search parameter in the booking list page is not sanitized or escaped in WP Hotel Booking versions older than 2.3.2. An attacker with a booking‑management role can manipulate the query and read or modify database contents.
Affected Systems
The affected product is the WP Hotel Booking WordPress plugin for all installations using a pre‑2.3.2 version. No other vendor or product is listed. Users with booking‑management capabilities are required to exploit the flaw.
Risk and Exploitability
The CVSS score of 6.8 indicates a medium level of risk. The EPSS figure of <1 % shows a very low probability of exploitation at present, and the issue is not in CISA’s KEV catalog. The attack requires authenticated access with at least booking‑management privileges; the vulnerable code runs under the website’s database user. Once accessed, an attacker can extract sensitive booking and customer data or alter it, potentially leading to data loss or a breach of privacy.
OpenCVE Enrichment