Impact
The vulnerability is an unauthenticated SQL Injection in JetBooking plugin versions 4.0.4.1 and earlier. Because authentication is not required, an attacker can supply crafted input through the plugin's public endpoints to execute arbitrary SQL statements. This can lead to reading, modifying or deleting sensitive data, potentially exposing customer information and compromising database integrity. The weakness is an input validation flaw categorized as CWE-89.
Affected Systems
The affected systems are websites that run WordPress with the JetBooking booking plugin from Crocoblock (Jetimpex Inc.) version 4.0.4.1 or older. The vulnerability exists in the plugin's database query handling code.
Risk and Exploitability
The CVSS score is 9.3, indicating a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is likely via the plugin's publicly accessible API or form endpoints, requiring no authentication. Exploitation would involve sending a malicious payload via ordinary web requests, making the vulnerability easy to discover and use by attackers with internet access.
OpenCVE Enrichment