WordPress · Pinpoint Booking System · CVE-2024-7112
**Name of the Vulnerable Software and Affected Versions**
The Pinpoint Booking System – #1 WordPress Booking Plugin versions up to, and including, 2.9.9.5.0
**Description**
The issue is related to SQL Injection via the `schedule` parameter due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
**Recommendations**
For versions up to, and including, 2.9.9.5.0, consider disabling the `schedule` parameter until a patch is available to prevent exploitation. Restrict access to the database to minimize the risk of sensitive information extraction. Update to a version that includes a fix for this issue once it becomes available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.