Sceawere

Vulnerability Detail

CVE-2026-103066UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Blind SQL Injection in WP BASE Booking

Vulnerability Metadata

Severity
High
Score / CVSS
8.5
Creation Date
1d ago
Vendor
WP BASE
Product
WP BASE Booking
Attack Type
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.5",
  "pubDate": "2026-10-05T20:17:08.027Z",
  "pubdate": "2026-10-05T20:17:08.027Z",
  "executiveSummary": "The WP BASE Booking plugin is susceptible to a Blind SQL Injection vulnerability, categorized under CWE-89 (Improper Neutralization of Special Elements used in an SQL Command).\nThis security flaw allows an unauthenticated or authenticated attacker to inject arbitrary SQL commands into the backend database by manipulating parameters processed by the plugin.\nThe vulnerability affects all versions of the WP BASE Booking plugin from n/a through 6.4.0.\nExploitation of this flaw enables an attacker to infer sensitive information from the database through boolean-based or time-based blind SQL injection techniques.\nThis impact can lead to unauthorized data exfiltration, including administrative credentials, user records, and sensitive business information contained within the WordPress database.\nThe risk is considered critical, as it bypasses standard application-layer security, providing attackers with the ability to interact directly with the database management system.",
  "technicalDetails": "The vulnerability stems from the improper sanitization and neutralization of user-supplied input before it is incorporated into SQL queries executed by the WP BASE Booking plugin.\nThe root cause is identified as the failure to utilize secure database abstraction layers, such as the WordPress $wpdb->prepare() method, when constructing queries.\nBy injecting malicious SQL syntax into vulnerable parameters, an attacker can manipulate the query logic, forcing the database to evaluate true/false conditions based on the attacker's input (Blind SQL Injection).\nThe attack flow typically involves the attacker identifying an input vector—such as a GET or POST parameter used in service or appointment filtering—and appending SQL fragments designed to elicit a predictable response from the application.\nIn a boolean-based attack, the attacker observes differences in the application's HTTP response (e.g., content length, specific error messages, or response timing) to determine whether an injected condition evaluates to true or false.\nBy iteratively testing characters, the attacker can reconstruct sensitive data stored in database tables, such as the site's 'wp_users' table or plugin-specific configuration settings.\nBecause this is a blind injection vector, the exploitation process is highly automated and does not require a direct visual output of the SQL query results; instead, it relies on observing the application's behavioral state after query execution.\nThe affected versions (n/a through 6.4.0) lack sufficient input validation controls, rendering the plugin unable to distinguish between legitimate user data and malicious SQL commands.\nThe attack can be performed remotely over the network, requiring no elevated privileges unless the specific input vector is gated by an authentication requirement; however, many such injection points are exposed to public-facing segments of the application.\nThe ultimate impact of a successful exploitation includes full database compromise, unauthorized modification of data, or potential escalation of access if the database service account possesses excessive permissions within the underlying operating system."
}
CVE-2026-103066: Blind SQL Injection in WP BASE Booking (HIGH Severity, CVSS: 8.5) | Sceawere