Junglewise Threat Intelligence

CVE-2026-15403: dotonpaper Pinpoint Booking System blind SQL injection in field parameter

CVE-2026-15403 · Severity: medium · CVSS 4.9 · Published 2026-08-01

Executive brief

The Pinpoint Booking System plugin for WordPress, which manages appointments and reservations, contains a security flaw that could allow an administrator to extract sensitive information from the website's database. While this requires administrative access, it represents a risk where a compromised or malicious high-level user could access data they are not authorized to view by bypassing standard database protections. The issue affects all versions of the plugin up to and including 2.9.9.6.9.

Technical details

A blind SQL injection vulnerability exists in the Pinpoint Booking System – Version 2 plugin for WordPress due to insufficient escaping of the 'field' parameter and a lack of SQL query preparation. The flaw is located within the backend calendar functionality, specifically affecting versions up to 2.9.9.6.9. An authenticated attacker with administrator-level privileges can exploit this by appending malicious SQL queries to existing database calls. Although administrative access is required, the necessary security nonce is easily obtainable from any plugin admin page loaded under manage_options. Successful exploitation allows for the extraction of sensitive data from the database via inference.

Affected products

  • dotonpaper Pinpoint Booking System – Version 2 0 to 2.9.9.6.9

Timeline

  • 2026-08-01: disclosed

References

Related threats