CVE-2026-103066
WP BASE Booking
Published 5 Oct 2026 · updated 5 Oct 2026 · Received
8.5 High · CVSS 3.1, patchstack.com
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0.