Executive brief
The Booking calendar plugin for WordPress, used to manage appointments and schedules, contains a security flaw that could allow unauthorized individuals to access sensitive database information. By sending specially crafted requests, an attacker can bypass security measures to extract data such as user details or site configurations. This vulnerability specifically affects the Pro version of the plugin when the 'Delete previous dates' feature is enabled.
Technical details
A time-based SQL injection vulnerability exists in the 'wpdevart_id' parameter of the Booking calendar plugin due to insufficient escaping and lack of SQL query preparation in the main_class.php file. Unauthenticated attackers can exploit this by appending malicious SQL commands to existing queries to exfiltrate data from the WordPress database. Exploitation requires the Pro version of the plugin to be active with the 'Delete previous dates' option enabled. The vulnerability is tracked as CWE-89 and affects all versions through 3.2.17.
Affected products
- wpdevart Booking calendar, Appointment Booking System (Pro) up to, and including, 3.2.17
Timeline
- 2026-07-10: disclosed: Initial publication of the CVE record
- 2026-07-10: advisory
References
- https://plugins.trac.wordpress.org/browser/booking-calendar/trunk/includes/main_class.php
- https://plugins.trac.wordpress.org/browser/booking-calendar/trunk/includes/main_class.php
- https://plugins.trac.wordpress.org/browser/booking-calendar/trunk/includes/main_class.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/8c052622-ac99-4069-b7df-41aea303ed9d?source=cve