CVE-2026-15335Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in all versions up to, and including, 1.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerable REST API endpoint /wp-json/booking-package/v1/request is registered with permission_callback: __return_true and wp_magic_quotes does not apply to REST-sourced $_POST values, meaning single quotes in the payload reach the SQL sink intact without any authentication requirement. The impact of this is severely limited as the vulnerable parameter goes through is_email.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-07-11); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-11: 2Mentions · 2026-07-12: 1Patch / Workaround · 2026-07-12: 1Technical Details · 2026-07-11: 2Technical Details · 2026-07-12: 107-1107-12
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-112
Disclosure2
2026-07-121
Patch1
Full discourse3 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    #CVE-2026-15335 - #SQLi in Booking Package for #WordPress. Unauthenticated attackers can extract sensitive #DB info. #CVSS 7.5. No patch available. Disable or replace immediately. #CVE #sysadmin #devsecops #devops #developers #git #gitlab #github #infosec https://www.valtersit.com/cve/CVE-2026-15335

    Post summary

    The post highlights CVE‑2026‑15335 as an unauthenticated SQL injection affecting a WordPress booking plugin, notes lack of an available patch, and recommends disabling or replacing the component.

    0000053
    978 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-15335 The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form

    Post summary

    The tweet announces a new CVE (2026-15335) affecting the WordPress Booking Package plugin, describing a generic SQL injection via the email form parameter, without providing any exploit code, patch, or evidence of active exploitation.

    0000042
    92 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-15335 The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form&lt;N&gt;) in all versions up to, and including, 1.7.20 due … https://www.cve.org/CVERecord?id=CVE-2026-15335

    Post summary

    The text announces that all Booking Package plugin versions 1.7.20 and older are vulnerable to a generic SQL Injection through the email form parameter.

    00000443
    57.8K followersView on X

Explore more