Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 01 Jul 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Repute Infosystems
Repute Infosystems bookingpress Appointment Booking Pro Wordpress Wordpress wordpress |
|
| Vendors & Products |
Repute Infosystems
Repute Infosystems bookingpress Appointment Booking Pro Wordpress Wordpress wordpress |
Wed, 01 Jul 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 01 Jul 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date' parameter of the bpa_assign_staffmember_to_slots() function in versions up to and including 5.7.1. This is due to the explicit use of stripslashes_deep() on user-supplied POST data before it is interpolated verbatim into a SQL LIKE clause without use of $wpdb->prepare() or any parameterization. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | |
| Title | BookingPress Appointment Booking Pro <= 5.7.1 - Unauthenticated SQL Injection via 'store_service_date' Parameter | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-07-01T10:42:10.506Z
Reserved: 2026-06-09T18:11:40.111Z
Link: CVE-2026-11823
Updated: 2026-07-01T10:33:30.799Z
Status : Deferred
Published: 2026-07-01T07:16:22.353
Modified: 2026-07-01T13:56:17.493
Link: CVE-2026-11823
No data.
OpenCVE Enrichment
Updated: 2026-07-01T13:45:02Z