Input validation vulnerability in Appointment Booking Calendar 1.2.24

The Appointment Booking Calendar plugin for WordPress is vulnerable to a type of attack called generic SQL Injection in versions up to and including 1.2.24. This means that unauthenticated attackers can use certain parameters in the plugin to add their own malicious SQL queries to existing queries. This can be used to gain access to and extract sensitive information from the website’s database.

Detected in:

Appointment Booking Calendar fixed vulnerable versions: >= * <= 1.2.24

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.