CVE-2026-91024
Booking Manager < 2.1.21 - Author+ SQLi via ICS Import Feed UID (sync_gid)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Booking Manager WordPress plugin before 2.1.21 does not sanitize and escape values taken from a fetched external iCalendar feed before using them in a SQL query, allowing authenticated users with Author-level access and above to perform SQL injection attacks by importing a feed they control.
| Vendor | unknown |
| Product | booking manager |
| Published | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown booking manager
Be the first to know when new unknown vulnerabilities affecting unknown booking manager are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Booking Manager
0 < 2.1.21
References
Credits
Mohamed Bassia WPScan