CVE-2026-91024
Received Received - Intake

SQL Injection in Booking Manager WordPress Plugin

Vulnerability report for CVE-2026-91024, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: WPScan

Description

The Booking Manager WordPress plugin before 2.1.21 does not sanitize and escape values taken from a fetched external iCalendar feed before using them in a SQL query, allowing authenticated users with Author-level access and above to perform SQL injection attacks by importing a feed they control.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
booking_manager booking_manager to 2.1.21 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Booking Manager WordPress plugin before version 2.1.21 has an SQL injection vulnerability. It fails to sanitize and escape values from an external iCalendar feed before using them in a SQL query. This allows authenticated users with Author-level access or higher to perform SQL injection attacks by importing a malicious ICS feed.

Detection Guidance

To detect this vulnerability, check the installed version of the Booking Manager WordPress plugin. If it is below 2.1.21, the system is vulnerable. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files directly.

Impact Analysis

This vulnerability allows attackers with Author-level access or higher to execute arbitrary SQL commands on your WordPress database. This could lead to unauthorized data access, modification, or deletion, potentially exposing sensitive information like user credentials or booking details.

Compliance Impact

This vulnerability could lead to data breaches, which may violate GDPR and HIPAA compliance requirements. Unauthorized access to personal or health data could result in legal penalties, fines, and reputational damage for organizations handling such data.

Mitigation Strategies

Immediately update the Booking Manager plugin to version 2.1.21 or later. Remove any unauthorized iCalendar feeds and restrict Author-level user permissions to minimize exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91024. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart