Executive brief
The Gravity Forms Booking plugin for WordPress, which adds appointment scheduling capabilities to websites, contains a security flaw. An attacker with a basic user account (such as a Subscriber) can exploit this to run unauthorized database commands. This could allow them to steal sensitive information stored in the website's database, potentially including customer details or site configuration data.
Technical details
The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL injection due to insufficient escaping of the 'staff_id' parameter and a lack of proper preparation in the existing SQL queries. This vulnerability allows authenticated attackers with Subscriber-level permissions or higher to append malicious SQL queries to legitimate ones. By leveraging time-based techniques, an attacker can exfiltrate sensitive data from the WordPress database. The issue affects all versions up to and including 2.7.1. A patch was released around June 24, 2026, following the disclosure.
Affected products
- GravityMore Gravity Bookings up to, and including, 2.7.1
Timeline
- 2026-06-24: patched: Changelog indicates updates on this date.
- 2026-06-25: disclosed
- 2026-06-25: advisory