External risk intelligence

Radius Booking Unauthenticated SQL Injection

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-39764

The vulnerability affects a booking and calendar plugin for web applications. Such plugins are designed to be public-facing to allow users to interact with scheduling and appointment services, making them a common internet-accessible component of a website.

SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in a popular web booking and calendar plugin, potentially allowing unauthenticated attackers to inject malicious SQL code. This could expose sensitive data or disrupt services. While the specific impact depends on your organization's use of this technology, it warrants attention to confirm relevance and exposure.

  • Allows unauthenticated attackers to inject code.
  • Potential for data exposure and service disruption.
  • Confirm if this booking system is in use.

Attack Path

How an attacker could exploit the issue

An attacker could target the booking calendar feature of a website to inject malicious SQL commands. This attack requires no prior authentication or special access to the website. If successful, the attacker could potentially access sensitive data stored in the database or cause disruptions to the booking system.

  • No authentication required.
  • Submit malicious SQL commands.
  • Data exposure and system disruption.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated SQL injection in the Radius Booking plugin could allow an attacker to read sensitive database information or potentially disrupt service, when supported by the advisory.

  • Database content could be exposed.
  • Network-based SQL injection is possible.
  • Unauthorized data access may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

This unauthenticated SQL injection vulnerability in a booking calendar plugin requires immediate attention from application owners and platform teams. The first step is to locate all instances of the affected plugin, determine their business criticality and external reachability, and identify the accountable system owner. Once ownership is confirmed, a risk-based remediation plan can be developed.

  • Application owners should own the issue.
  • Verify plugin presence and exposure.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Radius Booking plugin used for?

Radius Booking is a WordPress plugin designed to add appointment scheduling and service management functionality to websites. It allows site visitors to interact with a calendar interface to book times or services directly, serving as a dynamic, client-facing extension of a website's core database operations.

What does SQL injection mean for CVE-2026-39764?

This vulnerability is classified as CWE-89, which occurs when software improperly processes user input before including it in a database query. In this specific case, the plugin fails to sanitize data, allowing an attacker to insert their own malicious commands into the database, potentially leading to unauthorized data retrieval.

How does an attacker trigger this vulnerability?

An attacker triggers the flaw by sending crafted requests to the booking calendar feature. Because the vulnerability is unauthenticated, the attacker does not need a user account or special login credentials to interact with the plugin. Requests that do not interact with the vulnerable query functions will not trigger the bug.

Do I need to worry if my plugin is internal?

Halo Surface Signal indicates this plugin is typically internet-facing because its primary purpose is to allow public users to make appointments. While internal use is possible, the risk is highest for public-facing websites where the calendar is accessible to anyone on the internet, as this removes the need for the attacker to be inside your network.

What should I do first if I use Radius Booking?

Your first step is to perform an inventory of your web applications to confirm if the Radius Booking plugin is installed and active. Once identified, determine if the instance is reachable from the internet, assign an owner to the specific application, and prioritize the plugin for updates or replacement based on its business importance.

References