CVE-2026-11823Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date' parameter of the bpa_assign_staffmember_to_slots() function in versions up to and including 5.7.1. This is due to the explicit use of stripslashes_deep() on user-supplied POST data before it is interpolated verbatim into a SQL LIKE clause without use of $wpdb->prepare() or any parameterization. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-07-07)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-01: 1Mentions · 2026-07-07: 2Patch / Workaround · 2026-07-07: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-07: 207-0107-07
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-011
Disclosure1
2026-07-072
Disclosure1Patch1
Full discourse3 posts
  • yousukezan@yousukezan
    Disclosure

    BookingPress(CVE-2026-11823)未認証SQLインジェクションでDB露出──確認と対策 https://qiita.com/jiis-sasaki/items/85b6911ea058da04aa5f #Qiita @sitedock_jpより

    Post summary

    The post announces an unauthenticated SQL injection CVE-2026-11823 in BookingPress that can expose the database, and points to a Qiita article for confirmation and mitigation steps.

    021611.9K
    14.9K followersView on X
  • サイトドック|Webセキュリティ解説 一ノ瀬あかり@sitedock_jp
    Patch

    BookingPress 5.7.1以下に未認証で刺さるSQLインジェクション(CVE-2026-11823)。予約フォーム経由でDB内のユーザー名やパスワードハッシュを読み出されます。5.7.2への更新確認と、他プラグインにも効く恒久対策をまとめました。

    Post summary

    The text reports an unauthenticated SQL injection (CVE-2026-11823) in BookingPress 5.7.1 or older that allows credential extraction via the booking form, and it confirms that patching to version 5.7.2 and applying the outlined countermeasures mitigates the issue.

    1001051
    8 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-11823 SQL Injection in BookingPress Appointment Booking Pro Plugin Up to 5.7.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-11823

    Post summary

    This text announces the discovery of a SQL injection flaw in BookingPress Appointment Booking Pro up to version 5.7.1 and provides a link to vulnerability details, but does not mention any PoC, exploit, patch, or active exploitation.

    00000106
    4.1K followersView on X

Explore more