Impact
A flaw in the WordPress plugin Eagle Booking allows an attacker to inject arbitrary SQL statements because special characters are not properly neutralized. This vulnerability, classified as CWE‑89, can lead to the reading, modification, or deletion of data stored in the site's database. If an attacker can alter database contents, they may compromise the integrity of booking records or potentially elevate privileges to perform further attacks.
Affected Systems
The issue affects the Eagle‑Themes Eagle Booking WordPress plugin for all releases up to and including version 1.3.4.3. Users running these versions are exposed to the risk without an upgrade or patch.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, while the EPSS score of less than 1% suggests a low probability of mass exploitation at present. The vulnerability is exploitable over the web by submitting crafted input to plugin‑controlled parameters, making it a remote attack vector. The plug‑in is not listed in the CISA KEV catalog, so no documented real‑world exploitation has yet been reported.
OpenCVE Enrichment