CVE-2022-47428

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpDevArt Booking calendar, Appointment Booking System allows SQL Injection.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.7.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wpdevart:booking_calendar:*:*:*:*:*:wordpress:*:*

History

28 Apr 2026, 19:19

Type Values Removed Values Added
References
  • {'url': 'https://patchstack.com/database/Wordpress/Plugin/booking-calendar/vulnerability/wordpress-booking-calendar-appointment-booking-system-plugin-3-2-6-sql-injection?_s_id=cve', 'source': 'audit@patchstack.com'}
Summary (en) A vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.7. (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpDevArt Booking calendar, Appointment Booking System allows SQL Injection.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.7.

28 Apr 2026, 13:16

Type Values Removed Values Added
Summary (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpDevArt Booking calendar, Appointment Booking System allows SQL Injection.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.7. (en) A vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.7.
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 6.7
References
  • () https://patchstack.com/database/Wordpress/Plugin/booking-calendar/vulnerability/wordpress-booking-calendar-appointment-booking-system-plugin-3-2-6-sql-injection?_s_id=cve -

21 Nov 2024, 07:31

Type Values Removed Values Added
References () https://patchstack.com/database/vulnerability/booking-calendar/wordpress-booking-calendar-appointment-booking-system-plugin-3-2-6-sql-injection?_s_id=cve - Third Party Advisory () https://patchstack.com/database/vulnerability/booking-calendar/wordpress-booking-calendar-appointment-booking-system-plugin-3-2-6-sql-injection?_s_id=cve - Third Party Advisory

14 Nov 2023, 15:35

Type Values Removed Values Added
CPE cpe:2.3:a:wpdevart:booking_calendar:*:*:*:*:*:wordpress:*:*
References (MISC) https://patchstack.com/database/vulnerability/booking-calendar/wordpress-booking-calendar-appointment-booking-system-plugin-3-2-6-sql-injection?_s_id=cve - (MISC) https://patchstack.com/database/vulnerability/booking-calendar/wordpress-booking-calendar-appointment-booking-system-plugin-3-2-6-sql-injection?_s_id=cve - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Wpdevart booking Calendar
Wpdevart

06 Nov 2023, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-06 08:15

Updated : 2026-04-28 19:19


NVD link : CVE-2022-47428

Mitre link : CVE-2022-47428

CVE.ORG link : CVE-2022-47428


JSON object : View

Products Affected

wpdevart

  • booking_calendar
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')