SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-68566

CRITICAL · CVSS 9.3 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An unauthenticated SQL injection vulnerability exists in BookingPress Appointment Booking Pro versions up to 6.0.2, allowing attackers to manipulate database queries and potentially gain unauthorized access to sensitive data. This critical flaw poses a significant risk to any organization using the affected versions, making it imperative for users to prioritize immediate updates or mitigations to safeguard their systems.

CVE
CVE-2026-68566
Severity
CRITICAL
CVSS
9.3
EPSS
0.29%

Original NVD Description

Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.