Impact
The Booking calendar, Appointment Booking System plugin is vulnerable to a time‑based SQL injection through the wpdevart_id parameter. Insufficient escaping of this user‑supplied value allows an attacker to append malicious SQL clauses to the existing query, classified as CWE‑89. This flaw permits unauthenticated actors to read sensitive information from the database, potentially exposing user data, credentials, or other confidential data.
Affected Systems
The vulnerability affects all installations of the WordPress plugin Booking calendar, Appointment Booking System with version 3.2.17 or earlier. It only applies when the Pro edition is installed and activated, with the "Delete previous dates" option checked. Users of the free edition or installations that do not enable this option are not affected, but the plugin remains vulnerable under the stated conditions.
Risk and Exploitability
The CVSS score of 5.9 indicates a medium risk. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The attack vector is a simple HTTP request that includes a crafted wpdevart_id value; no authentication is required. Exploitation requires the Pro version with the "Delete previous dates" option enabled, after which an attacker can inject additional SQL and retrieve data. No public exploit has yet been reported, but the conditions for exploitation are clear and realistic.
OpenCVE Enrichment