External risk intelligence

WP BASE Booking SQL Injection Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-103352

This vulnerability affects a WordPress plugin designed for booking appointments, services, and events. Such plugins are typically installed on public-facing websites to allow user interaction, making the vulnerable functionality commonly reachable from the internet.

SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical SQL injection vulnerability has been identified in a WordPress plugin used for managing bookings, appointments, and events. This type of vulnerability can allow unauthorized access to sensitive data stored within the application's database. The primary concern is to confirm if this specific plugin is in use and, if so, to understand its exposure.

  • Allows unauthorized access to booking data.
  • Affects customer-facing appointment systems.
  • Confirm use and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted SQL queries to a booking plugin on a public-facing website. This allows them to interact with the vulnerable component without needing any special access. When successful, the vulnerability could lead to sensitive data exposure and denial of service.

  • Accessible via network.
  • Triggered by crafted SQL queries.
  • Risk of data exposure and denial of service.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to infer sensitive information from the booking system's database through blind SQL injection when supported by the advisory. This means an attacker could potentially gain insights into the system's data by sending specially crafted requests.

  • Database information could be at risk.
  • Exposure could happen via crafted input.
  • An attacker may gain unauthorized data.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given this SQL Injection vulnerability in the WP BASE Booking plugin, the first step is for infrastructure or platform teams to identify all instances of this plugin, confirm their internet reachability, and assess business criticality. The application owner responsible for the website where the plugin is deployed, or the vendor management team if it's a third-party service, should then be engaged to plan remediation or mitigation.

  • Identify plugin instances and assess exposure.
  • Confirm website owner and reachability.
  • Plan remediation or mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is WP BASE Booking?

WP BASE Booking is a WordPress plugin designed to help website administrators manage appointments, services, and events. It acts as a bridge between a public website and the site's database, allowing visitors to interact with booking calendars and scheduling features directly through their browsers.

What does SQL injection mean for CVE-2026-103352?

This vulnerability is classified as CWE-89, or Improper Neutralization of Special Elements used in an SQL Command. In plain terms, it means the plugin fails to properly filter user input before sending it to the database. An attacker can use this weakness to inject their own database commands, potentially allowing them to read sensitive information that should be hidden.

How is this SQL injection triggered?

The flaw is triggered by sending specially crafted web requests containing malicious SQL commands to the affected plugin. This does not happen through standard browsing activities; it requires an attacker to actively submit structured, harmful input to the booking component. Simply viewing a calendar or visiting a page that uses the plugin does not trigger the vulnerability.

Is my website at risk from this CVE?

According to Halo Surface Signal, this plugin is typically deployed on public-facing websites to facilitate user interactions like booking appointments. Because the plugin is designed to be accessible from the internet to serve customers, any site using an affected version is potentially reachable by attackers, making this a relevant concern for site owners.

What should I do if I use WP BASE Booking?

Your first step is to perform an inventory of your WordPress environments to identify if this plugin is installed and active. Once identified, confirm if the site is internet-facing and assess the sensitivity of the data managed by the plugin. Coordinate with your team to prioritize updates or disable the plugin until a secure version is confirmed.

References