Junglewise Threat Intelligence

CVE-2026-32466: Gravity Forms Bookings SQL injection in premium plugin

CVE-2026-32466 · Severity: high · CVSS 8.5 · Published 2026-08-18

Vendors: Gravity Forms.

Executive brief

Gravity Forms Bookings is a popular WordPress plugin that enables event booking and scheduling functionality on websites. A SQL injection vulnerability in version 2.1 and earlier allows authenticated subscribers to read, modify, or delete database records—including user accounts and sensitive customer information—potentially leading to data breaches or site takeover.

Technical details

A SQL injection (SQLi) vulnerability exists in Gravity Forms Bookings premium plugin version 2.1 and earlier. The vulnerability allows attackers with subscriber-level privileges to craft malicious queries that bypass database access controls. Attack preconditions include a valid WordPress account with subscriber privileges; no network-only exploitation is possible without authentication. An attacker can execute arbitrary SQL commands to read, modify, or delete database content, including sensitive user data and site configuration. As of the advisory date, no official patch was available; the vendor may have issued a fix in later versions beyond 2.1.

Affected products

  • Gravity Forms Bookings <= 2.1

Timeline

  • 2026-08-18: disclosed
  • 2026-08-17: advisory

References