CVE-2023-23991
The Booking Calendar plugin for WordPress contains a SQL injection vulnerability affecting versions through 9.4.2, stemming from improper sanitization of user input and inadequately prepared database queries. An authenticated attacker with administrative access could exploit this flaw by injecting malicious SQL code into an unspecified parameter, allowing them to execute arbitrary queries and potentially expose sensitive data stored in the database. The vulnerability was addressed in version 9.4.3.1 and later.
Based on public CVE data (MITRE/NVD).