yousukezan[verified]@yousukezanDisclosure
The post announces an unauthenticated SQL injection CVE-2026-11823 in BookingPress that can expose the database, and points to a Qiita article for confirmation and mitigation steps.
サイトドック|Webセキュリティ解説 一ノ瀬あかり@sitedock_jpPatch
The text reports an unauthenticated SQL injection (CVE-2026-11823) in BookingPress 5.7.1 or older that allows credential extraction via the booking form, and it confirms that patching to version 5.7.2 and applying the outlined countermeasures mitigates the issue.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
This text announces the discovery of a SQL injection flaw in BookingPress Appointment Booking Pro up to version 5.7.1 and provides a link to vulnerability details, but does not mention any PoC, exploit, patch, or active exploitation.