CVE-2026-11823

HIGH

BookingPress Appointment Booking Pro <= 5.7.1 - Unauthenticated SQL Injection via 'store_service_date' Parameter

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-11823. PoCs published by HermesNA-1.

AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-11823, a SQL injection vulnerability in the BookingPress Appointment Booking Pro WordPress plugin. The code includes metadata and a placeholder `run()` method but lacks actual exploit implementation or technical details about the vulnerability mechanics.

Description

The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date' parameter of the bpa_assign_staffmember_to_slots() function in versions up to and including 5.7.1. This is due to the explicit use of stripslashes_deep() on user-supplied POST data before it is interpolated verbatim into a SQL LIKE clause without use of $wpdb->prepare() or any parameterization. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Exploits (1)

github STUB 1 stars
by HermesNA-1 · pythonpoc
https://github.com/HermesNA-1/SnakeSploit/tree/main/data/modules_generated/cve-2026-11823_the_bookingpress_appointment.py

This repository contains an auto-generated stub module for CVE-2026-11823, a SQL injection vulnerability in the BookingPress Appointment Booking Pro WordPress plugin. The code includes metadata and a placeholder `run()` method but lacks actual exploit implementation or technical details about the vulnerability mechanics.

Classification
Stub 99%
Attack Type
Sqli
Complexity
Moderate
Reliability
Theoretical
Target: BookingPress Appointment Booking Pro plugin for WordPress (versions up to unspecified)
No auth needed
Prerequisites: WordPress site with vulnerable BookingPress plugin installed · Network access to the target (RHOSTS/RPORT)
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →

Scores

CVSS v3 7.5
EPSS 0.0029
EPSS Percentile 20.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
Repute Infosystems/BookingPress Appointment Booking Pro < 5.7.1
Published Jul 01, 2026
Tracked Since Jul 01, 2026