Executive brief
wpWax Directorist Booking is a WordPress plugin used to manage reservations and bookings on directory websites. A security flaw in this plugin allows an attacker with a basic user account to interact directly with the website's database. This could lead to the unauthorized theft of sensitive customer information or internal site data.
Technical details
A blind SQL injection vulnerability exists in the wpWax Directorist Booking plugin for WordPress due to improper neutralization of special elements in SQL commands. The flaw is present in versions up to and including 3.0.3. An attacker with at least 'Subscriber' level privileges can exploit this via network requests to perform unauthorized database queries. Successful exploitation allows for the extraction of sensitive data from the database, though it does not directly allow for data modification. The issue has been addressed in version 3.0.4.
Affected products
- wpWax Directorist Booking up to 3.0.3
Timeline
- 2026-05-26: other: Reported by researcher dutafi
- 2026-06-08: advisory: Patchstack advisory published
- 2026-06-17: disclosed: CVE published to NVD
- 2026-06-08: patched: Version 3.0.4 released to address the vulnerability