CVE-2026-13395: CWE-89 SQL Injection in Online Scheduling and Appointment Booking System
The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data such as password hashes from the database.
AI Analysis
Technical Summary
CVE-2026-13395 is a SQL injection vulnerability (CWE-89) in the Online Scheduling and Appointment Booking System WordPress plugin prior to version 27.8. The vulnerability arises from improper input validation and sanitization of a user-supplied parameter in unauthenticated booking requests, which is directly used in SQL queries. This allows attackers without authentication to execute arbitrary SQL commands, potentially leading to unauthorized data disclosure including sensitive information like password hashes.
Potential Impact
An unauthenticated attacker can exploit this vulnerability to perform SQL injection attacks against the plugin's database. This may result in unauthorized disclosure of sensitive data, including password hashes, which could lead to further compromise of user accounts or the system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vulnerability affects versions before 27.8, upgrading to version 27.8 or later is likely to address the issue once an official fix is released. Until then, restrict access to the affected plugin or disable it if possible to mitigate risk.
CVE-2026-13395: CWE-89 SQL Injection in Online Scheduling and Appointment Booking System
Description
The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data such as password hashes from the database.
CVSS v3.1
Score 8.6high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-13395 is a SQL injection vulnerability (CWE-89) in the Online Scheduling and Appointment Booking System WordPress plugin prior to version 27.8. The vulnerability arises from improper input validation and sanitization of a user-supplied parameter in unauthenticated booking requests, which is directly used in SQL queries. This allows attackers without authentication to execute arbitrary SQL commands, potentially leading to unauthorized data disclosure including sensitive information like password hashes.
Potential Impact
An unauthenticated attacker can exploit this vulnerability to perform SQL injection attacks against the plugin's database. This may result in unauthorized disclosure of sensitive data, including password hashes, which could lead to further compromise of user accounts or the system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vulnerability affects versions before 27.8, upgrading to version 27.8 or later is likely to address the issue once an official fix is released. Until then, restrict access to the affected plugin or disable it if possible to mitigate risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-06-26T08:07:05.201Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6aee089c2644c7f8a7ef2b
Added to database: 07/30/2026, 06:24:08 UTC
Last enriched: 07/30/2026, 06:55:10 UTC
Last updated: 07/30/2026, 23:36:57 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.