Input validation vulnerability in BMA Lite – Appointment Booking and Scheduling Plugin 1.4.2

The BMA Lite plugin for WordPress, up to version 1.4.2, has a security issue known as SQL Injection. This is because the plugin does not properly handle certain user inputs and does not adequately prepare for SQL queries. This vulnerability allows attackers who have administrator-level access or higher to add their own SQL queries to existing ones, potentially accessing sensitive information from the website’s database.

Detected in:

BMA Lite – Appointment Booking and Scheduling Plugin open vulnerable versions: >= * <= 1.4.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.