Vigil@nce - WordPress Booking System: SQL injection

This bulletin was written by Vigil@nce : http://vigilance.fr/offer

SYNTHESIS OF THE VULNERABILITY

An attacker can use a SQL injection of WordPress Booking System,
in order to read or alter data.

 Impacted products: WordPress Plugins
 Severity: 2/4
 Creation date: 21/05/2014

DESCRIPTION OF THE VULNERABILITY

The WordPress Booking System product uses a database.

However, user’s data are directly inserted in a SQL query.

An attacker can therefore use a SQL injection of WordPress Booking
System, in order to read or alter data.

ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN

http://vigilance.fr/vulnerability/WordPress-Booking-System-SQL-injection-14779

Articles similaires

Security Vulnerability

21 September 2026

Vigilance.fr - Linux kernel: nine vulnerabilities dated 21/07/2026

An attacker can use several vulnerabilities of the Linux kernel, dated 21/07/2026.

Security Vulnerability

20 September 2026

Vigilance.fr - RSYSLOG: buffer overflow via mmpstrucdata, analyzed on 20/07/2026

An attacker can trigger a buffer overflow of RSYSLOG, via mmpstrucdata, in order to trigger a (…)

Security Vulnerability

20 September 2026

Vigilance.fr - Linux kernel: multiple vulnerabilities dated 20/07/2026

An attacker can use several vulnerabilities of the Linux kernel, dated 20/07/2026.