Sceawere
Vulnerability Detail
CVE-2026-103352UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP BASE Booking SQL Injection
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.3
- Creation Date
- 2h ago
- Vendor
- WP BASE
- Product
- WP BASE Booking
- Attack Type
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.3",
"pubDate": "2026-10-05T19:17:13.847Z",
"pubdate": "2026-10-05T19:17:13.847Z",
"executiveSummary": "The WP BASE Booking plugin for WordPress is affected by an Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) vulnerability, specifically categorized as a Blind SQL Injection.\nThis vulnerability impacts versions from n/a through 6.4.0, posing a significant risk to the integrity and confidentiality of the database associated with the WordPress installation.\nAn unauthenticated or authenticated attacker can leverage this flaw to execute arbitrary SQL queries, leading to unauthorized data exfiltration.\nThe attack vector allows for the inference of database content bit-by-bit by observing the application's response behavior, making it a critical threat to data security.\nNo specific user interaction is explicitly required for successful exploitation if the entry point is exposed, and the impact may include the full compromise of the database contents, including sensitive user information and plugin configuration data.",
"technicalDetails": "The vulnerability resides within the query processing logic of the WP BASE Booking plugin, where user-supplied input is insufficiently sanitized or improperly parameterized before being concatenated into SQL statements.\nAs this is a Blind SQL Injection, the application does not directly return the results of the query in the HTTP response body. Instead, the attacker must rely on side-channel information, such as boolean-based or time-based indicators.\nThe attack flow begins when an attacker identifies an input vector within the plugin—such as parameters in a URL or POST request body—that influences database interactions. By injecting crafted SQL payloads containing conditional statements (e.g., CASE, IF) or time-delay functions (e.g., SLEEP(), BENCHMARK()), the attacker induces the application to behave differently based on the truth value of the injected condition.\nIn a boolean-based blind scenario, the attacker tests individual characters or bits of database data (e.g., table names, column names, or user passwords). If the injected condition is true, the server returns a standard page; if false, the server returns an error or a different response content. By iteratively refining these queries, the attacker can reconstruct sensitive data from the database.\nIn a time-based scenario, the attacker injects commands that instruct the database to pause for a specified duration if a certain condition is met. By measuring the response latency of the server, the attacker can infer the accuracy of their injected statements.\nSince the vulnerability is identified in all versions from n/a through 6.4.0, the root cause is a systemic failure in the plugin's data access layer to utilize prepared statements or parameterized queries provided by the WordPress wpdb class. Without proper use of $wpdb->prepare(), the plugin remains susceptible to manipulation of the query structure.\nSuccessful exploitation allows an attacker to bypass standard application logic, potentially leading to unauthorized data access, modification, or even full database administrative control if the database user permissions are overly permissive. Given the nature of WordPress plugins, this frequently results in the exfiltration of the entire wp_users table or sensitive plugin configuration."
}