Sceawere
Vulnerability Detail
CVE-2026-39764UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated SQL Injection in Radius Booking
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.3
- Creation Date
- 16h ago
- Vendor
- RadiusTheme
- Product
- Radius Booking — Booking Calendar for Appointments & Services
- Attack Type
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated SQL Injection in Radius Booking — Booking Calendar for Appointments & Services <= 1.0.19 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.3",
"pubDate": "2026-10-06T09:17:48.310Z",
"pubdate": "2026-10-06T09:17:48.310Z",
"executiveSummary": "The Radius Booking — Booking Calendar for Appointments & Services plugin, specifically versions 1.0.19 and below, contains a critical SQL Injection vulnerability.\nThis flaw allows unauthenticated remote attackers to manipulate database queries by injecting malicious SQL commands into vulnerable input parameters.\nThe vulnerability poses a severe risk to the confidentiality, integrity, and availability of the underlying WordPress database.\nSuccessful exploitation enables unauthorized actors to bypass authentication mechanisms, exfiltrate sensitive data, modify database records, or potentially achieve full administrative control over the application.\nThe attack requires no prior authentication or administrative privileges, making it accessible to any external threat actor with network access to the affected site.\nThe absence of sufficient input sanitization and parameter binding during the database query generation process is the primary factor facilitating this exploit.",
"technicalDetails": "The vulnerability resides within the request handling logic of the Radius Booking plugin, where user-supplied input parameters are concatenated directly into SQL queries without proper sanitization, escaping, or the use of prepared statements.\nThis improper implementation violates secure coding standards, allowing an attacker to escape the intended query structure and append arbitrary SQL commands, effectively performing a classic SQL Injection attack.\nThe attack flow begins when an unauthenticated actor sends a specially crafted HTTP request—typically via GET or POST methods—to the plugin's endpoint containing the vulnerable parameter. Because the application fails to validate the data type or content of this parameter, the injected payload is processed by the database management system (DBMS) as part of the primary query.\nExploitation allows for several post-exploitation maneuvers, including but not limited to UNION-based extraction of administrative credentials, sub-query data harvesting, or modification of site settings. If the database user utilized by the WordPress installation possesses high privileges (such as FILE permissions), an attacker might theoretically escalate their access to the server environment through functions like INTO OUTFILE.\nThe vulnerability is present in versions <= 1.0.19 and stems from the lack of robust sanitization functions (such as sanitize_sql_orderby or prepare()) when handling dynamic variables in SQL execution. By manipulating these parameters, the attacker controls the logic of the query, bypassing front-end restrictions entirely.\nBecause the vulnerable component is exposed via the public web interface, the attack surface is exposed to any network actor capable of reaching the web server. There are no secondary authorization barriers, as the vulnerable function is triggered before session verification protocols are enforced in the execution flow. The resulting data exfiltration or manipulation can have catastrophic effects on the integrity of the Booking Calendar data and the broader WordPress environment."
}