Input validation vulnerability in WP Booking Calendar 9.9

The WP Booking Calendar plugin for WordPress has a security issue called SQL Injection, which can happen in all versions up to 9.9. This happens because the plugin does not properly protect information entered by users and does not properly prepare the existing database. As a result, hackers can add their own code to existing code, which can then be used to access private information from the database.

Detected in:

WP Booking Calendar fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.