Impact
Gravity Forms Bookings premium plugin versions up to 2.1 contain a subscriber SQL Injection vulnerability. This flaw allows an attacker to inject arbitrary SQL through user‑supplied input, potentially retrieving, altering, or deleting database records. The injection could be leveraged to compromise the integrity and confidentiality of the site’s data, but no direct remote code execution is disclosed.
Affected Systems
The vulnerability affects WordPress sites that have the WPExperts Gravity Forms Bookings premium plugin installed in versions 2.1 or earlier. Any installation of this plugin within that version range is at risk.
Risk and Exploitability
With a CVSS score of 8.5 the flaw is rated high severity. The EPSS score is not available, indicating limited publicly known exploitation data. The CVE is not listed in the CISA KEV catalog. Attackers with web access can trigger the injection by submitting crafted input to the Gravity Forms Bookings entry points; the vector is inferred to be remote via the web interface, requiring the victim to be running the vulnerable plugin.
OpenCVE Enrichment