CVE-2024-10856
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2024-10856: The WpDevArt Booking Calendar plugin, before version 3.2.20, is susceptible to time-based, blind SQL injection. This vulnerability arises due to insufficient escaping of user-supplied data in the `id` parameter of the `wpdevart_booking_calendar` shortcode and the absence of sufficient preparation of existing SQL queries. Authenticated attackers with contributor-level access or above can exploit this issue by appending additional SQL queries, which can be used to extract sensitive information like passwords from the database. The vulnerability is exacerbated when the "delete_prev_date" theme option is enabled.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.