CVE-2024-10856

The Booking Calendar WpDevArt plugin is vulnerable to time-based, blind SQL injection via the `id` parameter in the “wpdevart_booking_calendar” shortcode in versions up to, and including, 3.2.19 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. The vulnerability requires the “delete_prev_date” theme option being enabled. This makes it possible for authenticated attackers, with contributor-level access or above, to append additional SQL queries into already existing query that can be used to extract sensitive information such as passwords from the database.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wpdevart:booking_calendar:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2024-12-24 11:15

Updated : 2025-03-21 18:50


NVD link : CVE-2024-10856

Mitre link : CVE-2024-10856

CVE.ORG link : CVE-2024-10856


JSON object : View

Products Affected

wpdevart

  • booking_calendar
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')