Impact
The plugin’s subscriber form accepts input that is directly incorporated into database queries without proper sanitization, leading to a classic SQL injection weakness. An attacker can insert arbitrary SQL code, potentially viewing, modifying, or deleting data stored by WordPress. This exploitation could compromise the confidentiality and integrity of the site’s database and may serve as a foothold for further attacks depending on the attacker’s privileges.
Affected Systems
WordPress installations running the WP Time Slots Booking Form plugin version 1.2.50 or older, as provided by the vendor Codepeople.
Risk and Exploitability
With a CVSS score of 8.5 the vulnerability is considered high severity, yet its EPSS score of less than 1% indicates a low probability of exploitation in the wild so far. Nevertheless, the vulnerability is listed as a standard SQL injection (CWE-89) and is not included in the CISA KEV catalog. An attacker would most likely exploit the vulnerability via the public-facing subscriber form, requiring no special privileges and leveraging the web application’s database interface.
OpenCVE Enrichment