What is CVE-2026-13395?
CVE-2026-13395 is an unauthenticated SQL injection vulnerability in the "Online Scheduling and Appointment Booking System" WordPress plugin before version 27.8. Attackers can manipulate database queries via unsanitized user-supplied parameters in booking requests. Immediate plugin update is recommended.
Azərbaycanca: CVE-2026-13395 “Online Scheduling and Appointment Booking System” adlı WordPress plaqininin 27.8 versiyasından əvvəlki versiyalarında autentifikasiya olunmamış SQL injection zəifliyidir. Təcavüzkar xüsusi sorğular göndərərək verilənlər bazasına müdaxilə edə bilər. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which WordPress plugin is affected by CVE-2026-13395?
This vulnerability affects the "Online Scheduling and Appointment Booking System" plugin.
To what version should the plugin be updated to protect against this SQL injection vulnerability?
It is recommended to update the plugin to version 27.8 or higher.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.