Vulnerability Description
The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data such as password hashes from the database.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-13395?
CVE-2026-13395 is a vulnerability with a CVSS score of 8.6 (HIGH). The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests befo...
How severe is CVE-2026-13395?
CVE-2026-13395 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-13395?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.