Description
Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.
Published: 2026-08-18
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Gravity Forms Bookings premium plugin versions up to 2.1 contain a subscriber SQL Injection vulnerability. This flaw allows an attacker to inject arbitrary SQL through user‑supplied input, potentially retrieving, altering, or deleting database records. The injection could be leveraged to compromise the integrity and confidentiality of the site’s data, but no direct remote code execution is disclosed.

Affected Systems

The vulnerability affects WordPress sites that have the WPExperts Gravity Forms Bookings premium plugin installed in versions 2.1 or earlier. Any installation of this plugin within that version range is at risk.

Risk and Exploitability

With a CVSS score of 8.5 the flaw is rated high severity. The EPSS score is not available, indicating limited publicly known exploitation data. The CVE is not listed in the CISA KEV catalog. Attackers with web access can trigger the injection by submitting crafted input to the Gravity Forms Bookings entry points; the vector is inferred to be remote via the web interface, requiring the victim to be running the vulnerable plugin.

Generated by OpenCVE AI on August 18, 2026 at 15:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Gravity Forms Bookings premium to the latest version (≥2.2) to remove the injection flaw.
  • If an upgrade cannot be performed immediately, disable the Gravity Forms Bookings premium plugin on production sites until the patch is applied.
  • Implement web application firewall rules that block common SQL injection payloads targeting the Gravity Forms Bookings plugin endpoints.

Generated by OpenCVE AI on August 18, 2026 at 15:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.
Title WordPress Gravity Forms Bookings premium plugin <= 2.1 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T15:30:14.411Z

Reserved: 2026-03-12T11:11:45.409Z

Link: CVE-2026-32466

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T14:17:03.787

Modified: 2026-08-18T14:17:03.787

Link: CVE-2026-32466

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T15:30:05Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')