Impact
Vulnerability in Pinpoint Booking System – Version 2 allows blind SQL Injection through the 'field' parameter. The attacker can append new SQL statements to existing queries because user input is not properly escaped or prepared. This leads to the extraction of sensitive database information for authenticated users who have administrator-level privileges. The exploit is limited to authenticated administrators, but it can compromise data confidentiality.
Affected Systems
WordPress sites running the Pinpoint Booking System – Version 2 plugin with any version up to and including 2.9.9.6.9. The vendor is dotonpaper and the affected product is the Pinpoint Booking System – Version 2 plugin.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity, while the EPSS score of less than 1% shows a very low probability of exploitation at this time. The vulnerability is not currently listed in the CISA KEV catalog. Attackers must be authenticated administrators, which reduces the attack surface, but once privilege is achieved the impact can be significant.
OpenCVE Enrichment