← Vulnerability feed

Vulnerability record · CVE-2018-20556 · published 21 March 2019

CVE-2018-20556: Booking calendar project booking calendar sql injection vulnerability

Booking Calendar Project · Booking Calendar

SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter.

8.8 CVSS 3.0 High EPSS 19% · top 2.8% CWE-89 · SQL injection
8.8CVSS 3.0 base score, v2 6.5
19%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-20556 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-1463Booking calendar project booking calendar deserialization of untrusted data vulnerabilityThe Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and includ…EPSS 1.7%8.8CVE-2018-5673Booking calendar project booking calendar cross-site request forgery vulnerabilityAn issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. CSRF exists via wp-admin/admin.php.EPSS 0.77%6.1CVE-2023-36384Booking calendar project booking calendar cross-site scripting vulnerabilityUnauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodePeople Booking Calendar Contact Form plugin <= 1.2.40 versions.EPSS 0.41%6.1CVE-2021-25040Booking calendar project booking calendar cross-site scripting vulnerabilityThe Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page…EPSS 0.80%6.1CVE-2017-2151Booking calendar project booking calendar cross-site scripting vulnerabilityCross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via uns…EPSS 0.85%5.3CVE-2017-2150Booking calendar project booking calendar path traversal vulnerabilityDirectory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary files via specially crafted c…EPSS 2.4%4.8CVE-2018-5671Booking calendar project booking calendar cross-site scripting vulnerabilityAn issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php extra_field1[items][field_item1][pr…EPSS 0.62%4.8CVE-2018-5672Booking calendar project booking calendar cross-site scripting vulnerabilityAn issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php form_field5[label] parameter.EPSS 0.62%

Source: NIST National Vulnerability Database (record CVE-2018-20556), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.