CVE-2024-10856
24.12.2024, 11:15
The Booking Calendar WpDevArt plugin is vulnerable to time-based, blind SQL injection via the `id` parameter in the wpdevart_booking_calendar shortcode in versions up to, and including, 3.2.19 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. The vulnerability requires the delete_prev_date theme option being enabled. This makes it possible for authenticated attackers, with contributor-level access or above, to append additional SQL queries into already existing query that can be used to extract sensitive information such as passwords from the database.
Vendor | Product | Version |
---|---|---|
wpdevart | booking_calendar | 𝑥 < 3.2.0 |
𝑥
= Vulnerable software versions
References