OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-103066

HIGH · CVSS 8.5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A SQL Injection vulnerability in the WP BASE Booking plugin allows for blind SQL injection attacks, potentially enabling unauthorized access to the database and manipulation of sensitive data. This high-severity flaw affects versions up to 6.4.0 and should be prioritized by organizations using this plugin to mitigate the risk of data breaches and unauthorized data manipulation. Immediate action is recommended to patch or upgrade to a secure version.

CVE
CVE-2026-103066
Severity
HIGH
CVSS
8.5
EPSS
0.26%

Original NVD Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0.