CVE-2026-1719Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.5.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-05-06); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-06: 3Mentions · 2026-05-29: 1Technical Details · 2026-05-06: 305-0605-29
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-063
Disclosure3
2026-05-291
General1
Full discourse4 posts
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【脆弱性情報】 CVE-2026-1719 Gravity Bookings Premiumの脆弱性について https://www.cybernote.click/2026/05/19/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-1719-gravity-bookings-premium%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6/ #IT #Security #cybersecurity

    Post summary

    The tweet merely announces the existence of CVE‑2026‑1719 in Gravity Bookings Premium and directs readers to an external link for more information, providing no technical or remediation details.

    0000040
    208 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-1719 The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.5.9 due to insufficient escaping on the user su… https://www.cve.org/CVERecord?id=CVE-2026-1719 ----- Traducción: CVE-2026-1719 El … http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-1719 for the Gravity Bookings Premium plugin, describing a SQL injection flaw in all versions up to 2.5.9, but offers no PoC, exploit, or patch information.

    0000043
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1719 The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.5.9 due to insufficient escaping on the user su… https://www.cve.org/CVERecord?id=CVE-2026-1719

    Post summary

    The Gravity Bookings Premium plugin for WordPress is reported to be vulnerable to SQL injection in all versions up to 2.5.9, with no evidence of PoC, exploit tool, active exploitation, patch, or debunking.

    00000173
    57.4K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-1719 The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, … CVSS 7.5 Full analysis → https://sec.kaitan.id/cves/CVE-2026-1719 #WordPress #CyberSecurity #InfoSec

    Post summary

    The post announces a high‑severity (CVSS 7.5) SQL injection flaw in Gravity Bookings Premium (CVE‑2026‑1719), but provides no PoC, exploit code, patch, or evidence of active attacks.

    0000053
    483 followersView on X

Explore more