Executive brief
The Court Reservation plugin for WordPress, which manages online sports court bookings, contains a security flaw that allows unauthorized access to database information. An attacker can exploit this to steal sensitive data from the website's database without needing a login. This could lead to the exposure of customer information, booking details, or other private site data.
Technical details
The Court Reservation plugin for WordPress is vulnerable to SQL Injection due to insufficient escaping of the 'id' parameter and a lack of SQL query preparation in the public-facing component. This vulnerability allows unauthenticated attackers to append malicious SQL commands to existing queries via a network request. Successful exploitation enables the extraction of sensitive information from the WordPress database. The flaw is present in all versions up to and including 1.10.11.
Affected products
- Court Reservation Court Reservation – Manage Your Court Bookings Online Up to and including 1.10.11
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory