Executive brief
JetBooking is a WordPress plugin used to manage booking and rental services on websites. A critical security flaw allows unauthorized individuals to send malicious commands to the website's database without needing a login. This could lead to the theft of sensitive customer information, unauthorized access to site data, or disruption of booking services.
Technical details
An unauthenticated SQL injection vulnerability exists in the JetBooking plugin for WordPress (versions <= 4.0.4.1). The flaw is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), allowing a remote attacker to execute arbitrary SQL queries via the network without any prior authentication or user interaction. This can lead to full database compromise, including sensitive data exfiltration. The vulnerability was addressed in version 4.0.4.2.
Affected products
- Crocoblock. Jetimpex Inc. JetBooking <= 4.0.4.1
Timeline
- 2026-04-24: other: Vulnerability reported by researcher daroo
- 2026-06-17: advisory: Initial disclosure by Patchstack
- 2026-06-26: disclosed: CVE published to NVD dataset
- 2026-06-26: patched: Patch available in version 4.0.4.2