Sceawere

Vulnerability Detail

CVE-2026-39764UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated SQL Injection in Radius Booking

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.3
Creation Date
16h ago
Vendor
RadiusTheme
Product
Radius Booking — Booking Calendar for Appointments & Services
Attack Type
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated SQL Injection in Radius Booking — Booking Calendar for Appointments &amp; Services <= 1.0.19 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.3",
  "pubDate": "2026-10-06T09:17:48.310Z",
  "pubdate": "2026-10-06T09:17:48.310Z",
  "executiveSummary": "The Radius Booking — Booking Calendar for Appointments & Services plugin, specifically versions 1.0.19 and below, contains a critical SQL Injection vulnerability.\nThis flaw allows unauthenticated remote attackers to manipulate database queries by injecting malicious SQL commands into vulnerable input parameters.\nThe vulnerability poses a severe risk to the confidentiality, integrity, and availability of the underlying WordPress database.\nSuccessful exploitation enables unauthorized actors to bypass authentication mechanisms, exfiltrate sensitive data, modify database records, or potentially achieve full administrative control over the application.\nThe attack requires no prior authentication or administrative privileges, making it accessible to any external threat actor with network access to the affected site.\nThe absence of sufficient input sanitization and parameter binding during the database query generation process is the primary factor facilitating this exploit.",
  "technicalDetails": "The vulnerability resides within the request handling logic of the Radius Booking plugin, where user-supplied input parameters are concatenated directly into SQL queries without proper sanitization, escaping, or the use of prepared statements.\nThis improper implementation violates secure coding standards, allowing an attacker to escape the intended query structure and append arbitrary SQL commands, effectively performing a classic SQL Injection attack.\nThe attack flow begins when an unauthenticated actor sends a specially crafted HTTP request—typically via GET or POST methods—to the plugin's endpoint containing the vulnerable parameter. Because the application fails to validate the data type or content of this parameter, the injected payload is processed by the database management system (DBMS) as part of the primary query.\nExploitation allows for several post-exploitation maneuvers, including but not limited to UNION-based extraction of administrative credentials, sub-query data harvesting, or modification of site settings. If the database user utilized by the WordPress installation possesses high privileges (such as FILE permissions), an attacker might theoretically escalate their access to the server environment through functions like INTO OUTFILE.\nThe vulnerability is present in versions <= 1.0.19 and stems from the lack of robust sanitization functions (such as sanitize_sql_orderby or prepare()) when handling dynamic variables in SQL execution. By manipulating these parameters, the attacker controls the logic of the query, bypassing front-end restrictions entirely.\nBecause the vulnerable component is exposed via the public web interface, the attack surface is exposed to any network actor capable of reaching the web server. There are no secondary authorization barriers, as the vulnerable function is triggered before session verification protocols are enforced in the execution flow. The resulting data exfiltration or manipulation can have catastrophic effects on the integrity of the Booking Calendar data and the broader WordPress environment."
}
CVE-2026-39764: Unauthenticated SQL Injection in Radius Booking (CRITICAL Severity, CVSS: 9.3) | Sceawere