CVE-2026-1250Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Court Reservation – Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.10.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-05-13)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-12: 1Mentions · 2026-05-13: 2Technical Details · 2026-05-12: 1Technical Details · 2026-05-13: 205-1205-13
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-121
Disclosure1
2026-05-132
Disclosure2
Full discourse3 posts
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-1250 The Court Reservation – Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injection v… CVSS 7.5 Full analysis → https://sec.kaitan.id/cves/CVE-2026-1250 #WordPress #CyberSecurity #InfoSec

    Post summary

    The post publicly discloses a high‑severity SQL injection vulnerability (CVE‑2026‑1250) affecting the Court Reservation WordPress plugin, including its CVSS score and a link to a detailed analysis.

    0000056
    90 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1250 SQL Injection in Court Reservation – Manage Your Court Bookings Online Plugin 1.10.11 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1250

    Post summary

    A new SQL injection vulnerability (CVE‑2026‑1250) has been disclosed for the Court Reservation WordPress plugin, version 1.10.11, with no evidence of exploitation, PoC, or patch information yet reported.

    0000049
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1250 The Court Reservation – Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in all versions up to, and … https://www.cve.org/CVERecord?id=CVE-2026-1250

    Post summary

    The post announces CVE-2026-1250 as a generic SQL injection flaw in the Court Reservation WordPress plugin via the 'id' parameter; no PoC, exploit, patch, or active exploitation details are provided.

    0000085
    57.5K followersView on X

Explore more