Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-76226
HistoryApr 13, 2022 - 12:00 a.m.

WordPress Advanced Booking Calendar before plugin SQL injection vulnerability

2022-04-1300:00:00
China National Vulnerability Database
www.cnvd.org.cn
4

0.001 Low

EPSS

Percentile

41.2%

WordPress is a set of blogging platforms developed by the Wordpress Foundation using the PHP language. WordPress plugin is an application plugin for WordPress. WordPress Advanced Booking Calendar before plugin version 1.7.1 is vulnerable to a SQL injection vulnerability that stems from The plugin fails to clean up and escape the id parameter when editing the calendar. An attacker could exploit this vulnerability to perform SQL injection attacks.

0.001 Low

EPSS

Percentile

41.2%