High severity8.8NVD Advisory· Published Mar 21, 2019· Updated Jun 17, 2026
CVE-2018-20556
CVE-2018-20556
Description
SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: = 8.4.3
- cpe:2.3:a:booking_calendar_project:booking_calendar:8.4.3:*:*:*:*:wordpress:*:*
- Range: =8.4.3
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/151692/WordPress-Booking-Calendar-8.4.3-SQL-Injection.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/46377/nvdExploitThird Party AdvisoryVDB Entry
- gist.github.com/B0UG/a750c2c204825453e6faf898ea6d09f6nvd
- vulners.com/exploitdb/EDB-ID:46377nvd
News mentions
0No linked articles in our index yet.