Input validation vulnerability in Advanced Booking Calendar 1.6.2

The Advanced Booking Calendar plugin for WordPress is a software that can be installed on a website. Unfortunately, this plugin has a security flaw in versions 1.6.1 and earlier. This flaw makes it possible for attackers, if they are authenticated, to access sensitive information from the website’s database. This happens because the plugin is not properly escaping user supplied parameters and not preparing existing SQL queries, both of which are essential for keeping the website secure.

Detected in:

Advanced Booking Calendar open vulnerable versions: >= * < 1.6.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.