Junglewise Threat Intelligence

CVE-2026-48882: CodePeople WP Time Slots Booking Form SQL injection

CVE-2026-48882 · Severity: high · CVSS 8.5 · Published 2026-06-15

Vendors: CodePeople.

Executive brief

The WP Time Slots Booking Form plugin for WordPress, which allows websites to manage appointment scheduling, contains a security flaw that could allow logged-in users to access sensitive database information. An attacker with a basic 'Subscriber' account could exploit this to steal customer data or other confidential information stored in the site's database. This could lead to data breaches and significant reputational damage for businesses relying on the booking system.

Technical details

A SQL injection vulnerability exists in the WP Time Slots Booking Form plugin for WordPress due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is present in versions up to and including 1.2.50. An authenticated attacker with Subscriber-level privileges can send specially crafted network requests to execute arbitrary SQL queries against the backend database. This can result in the unauthorized extraction of sensitive information, including user credentials and site configuration. The issue is addressed in version 1.2.51.

Affected products

  • CodePeople WP Time Slots Booking Form <= 1.2.50

Timeline

  • 2026-05-16: other: Reported by researcher xwii
  • 2026-06-02: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date
  • 2026-06-02: patched: Version 1.2.51 released

References

Related threats