The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query via the bookingpress_front_get_category_services AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection
PoC: CVE-2022-0739
BookingPress < 1.0.11 - Unauthenticated SQL Injection
PoC: CVE-2022-0739
Exploit for WP BookingPress (< 1.0.11) based on destr4ct POC.
PoC: wp_bookingpress_1.0.11
CVE-2022-0739 Wordpress BookingPress Plugin < 1.0.11
PoC: CVE-2022-0739
Python Exploit for CVE-2022-0739
PoC: CVE-2022-0739
Simple bash script to automate the exploit of cve 2022 0739
PoC: CVE-2022-0739
Proof-of-Concept exploit (SQLI BookingPress before 1.0.11)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free