
CVE-2025-8781 The Bookster – WordPress Appointment Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘raw’ parameter in all versions up to, and including, 2.… https://www.cve.org/CVERecord?id=CVE-2025-8781
Post summary
The Bookster WordPress Appointment Booking Plugin is vulnerable to SQL injection via the ‘raw’ parameter in all versions up to 2.x, but no PoC, exploit tool, patch, or evidence of active exploitation is mentioned.
