PT-2026-49206 · WordPress · Booking-Calendar-Contact-Form

CVE-2016-20068

·

Published

2016-02-08

·

Updated

2026-06-15

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions WordPress Booking Calendar Contact Form versions prior to 1.0.24
Description An unauthenticated blind SQL injection exists due to insufficient escaping of user-supplied parameters and lack of preparation in SQL queries. This allows remote attackers to execute arbitrary SQL queries and extract sensitive database information. The issue occurs when sending requests to the 'admin-ajax.php' endpoint with the action parameter set to 'dex bccf calendar ajaxevent' and injecting malicious code through the id or calendar parameters.
Recommendations Update WordPress Booking Calendar Contact Form to a version newer than 1.0.23. Avoid using the id and calendar parameters in the 'admin-ajax.php' endpoint until the update is applied.

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-20068

Affected Products

Booking-Calendar-Contact-Form