8.8
CVSSv3

CVE-2018-20556

Published: 21/03/2019 Updated: 09/05/2019
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote malicious users to execute arbitrary SQL commands via the booking_id parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

booking calendar project booking calendar 8.4.3

Exploits

# Exploit Title: Wordpress Booking Calendar v843 - Authenticated SQL Injection Vulnerability # Date: 2018-12-28 # Exploit Author: B0UG # Vendor Homepage: wpbookingcalendarcom/ # Software Link: wordpressorg/plugins/booking/ # Version: Tested on version 843 (older versions may also be affected) # Tested on: WordPress # Category ...
WordPress Booking Calendar version 843 suffers from a remote SQL injection vulnerability ...