CVE-2024-10856
EUVD-2024-3355724.12.2024, 11:15
The Booking Calendar WpDevArt plugin is vulnerable to time-based, blind SQL injection via the `id` parameter in the “wpdevart_booking_calendar” shortcode in versions up to, and including, 3.2.19 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. The vulnerability requires the “delete_prev_date” theme option being enabled. This makes it possible for authenticated attackers, with contributor-level access or above, to append additional SQL queries into already existing query that can be used to extract sensitive information such as passwords from the database.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| wpdevart | booking_calendar | 𝑥 < 3.2.0 |
𝑥
= Vulnerable software versions
References