CVE-2026-11823
HIGHBookingPress Appointment Booking Pro <= 5.7.1 - Unauthenticated SQL Injection via 'store_service_date' Parameter
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-11823. PoCs published by HermesNA-1.
AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-11823, a SQL injection vulnerability in the BookingPress Appointment Booking Pro WordPress plugin. The code includes metadata and a placeholder `run()` method but lacks actual exploit implementation or technical details about the vulnerability mechanics.
Description
The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date' parameter of the bpa_assign_staffmember_to_slots() function in versions up to and including 5.7.1. This is due to the explicit use of stripslashes_deep() on user-supplied POST data before it is interpolated verbatim into a SQL LIKE clause without use of $wpdb->prepare() or any parameterization. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Exploits (1)
This repository contains an auto-generated stub module for CVE-2026-11823, a SQL injection vulnerability in the BookingPress Appointment Booking Pro WordPress plugin. The code includes metadata and a placeholder `run()` method but lacks actual exploit implementation or technical details about the vulnerability mechanics.
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N