What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Booking Calendar | Appointment Booking | BookIt.This issue affects Booking Calendar | Appointment Booking | BookIt: from n/a through 2.4.3.
Explanation of Vulnerability in Simple Terms
02Summary
A SQL injection vulnerability in Booking Calendar allows authenticated administrators to execute arbitrary SQL queries against the site database. An attacker with high-level admin privileges can read sensitive data or disrupt database operations. The vulnerability requires admin access and does not affect data integrity. Update to a version newer than 2.4.3.
What an attacker can do
03Attacker Capabilities
Execute SQL queries to read database contents or cause service disruption.
Potential impact on your site
04Site Impact
Admin accounts are at risk; compromised admins can extract sensitive data or degrade site availability.
Conditions required to exploit
05Prerequisites
Attacker must have high-level administrator privileges on the site.
Key dates
06Disclosure timeline
December 28, 2023
CVE published
April 28, 2026
Record updated