CVE Database /
CVE-2026-49073
CVE · High
CVE-2026-49073 — Directorist Booking [directorist-booking] < 3.0.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-49073
|
Directorist Booking [directorist-booking] < 3.0.4 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
High
8.5
|
< 3.0.4
|
3.0.4 |
2026-06-08 |
—
|
CVE-2026-49073
The Booking plugin for WordPress has a weakness in its handling of user input, specifically in how it combines external data with internal database queries. As a result, attackers who have logged in and possess at least subscriber-level privileges can inject malicious SQL code into existing queries, potentially allowing them to access sensitive information stored within the database. This vulnerability affects versions 3.0.3 and earlier of the plugin.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings