PT-2026-49206 · WordPress · Booking-Calendar-Contact-Form
CVE-2016-20068
·
Published
2016-02-08
·
Updated
2026-06-15
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WordPress Booking Calendar Contact Form versions prior to 1.0.24
Description
An unauthenticated blind SQL injection exists due to insufficient escaping of user-supplied parameters and lack of preparation in SQL queries. This allows remote attackers to execute arbitrary SQL queries and extract sensitive database information. The issue occurs when sending requests to the 'admin-ajax.php' endpoint with the
action parameter set to 'dex bccf calendar ajaxevent' and injecting malicious code through the id or calendar parameters.Recommendations
Update WordPress Booking Calendar Contact Form to a version newer than 1.0.23.
Avoid using the
id and calendar parameters in the 'admin-ajax.php' endpoint until the update is applied.Fix
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Booking-Calendar-Contact-Form