SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13395

HIGH · CVSS 8.6 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The Online Scheduling and Appointment Booking System plugin for WordPress versions prior to 27.8 is vulnerable to SQL injection due to inadequate sanitization of user-supplied parameters in unauthenticated front-end booking requests. This flaw allows attackers to execute arbitrary SQL queries, potentially leading to the extraction of sensitive data, including password hashes. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of data breaches.

CVE
CVE-2026-13395
Severity
HIGH
CVSS
8.6
EPSS
0.34%
WordPress

Original NVD Description

The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data such as password hashes from the database.