PT-2022-27649 · WordPress · Advanced Booking Calendar

Minhtuanact

·

Published

2022-12-05

·

Updated

2022-12-06

·

CVE-2022-45822

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advanced Booking Calendar plugin version 1.7.1 and earlier
Description The issue is related to an Unauth. SQL Injection (SQLi) vulnerability. This means that an unauthorized user can potentially inject malicious SQL code, which could lead to unauthorized access or modification of database content.
Recommendations For Advanced Booking Calendar plugin version 1.7.1 and earlier, update to a version later than 1.7.1 to resolve the issue.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-45822

Affected Products

Advanced Booking Calendar