What is CVE-2026-15403?
CVE-2026-15403 is a Blind SQL Injection vulnerability in the Pinpoint Booking System plugin for WordPress, affecting versions up to 2.9.9.6.9. This flaw exists via the 'field' parameter due to insufficient escaping of user-supplied input and lack of proper preparation of the existing SQL query. Immediate update to the latest patched version is recommended.
Azərbaycanca: CVE-2026-15403 WordPress üçün Pinpoint Booking System 2.9.9.6.9-a qədər versiyalarında 'field' parametri vasitəsilə Blind SQL Injection zəifliyidir. Bu zəiflik istifadəçi tərəfindən təqdim edilən parametrin kifayət qədər escap edilməməsi və mövcud SQL sorğusuna hazırlığın olmaması səbəbindən yaranır. Təcili olaraq plugin-in ən son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the WordPress Pinpoint Booking System are affected by CVE-2026-15403?
This vulnerability affects versions of the Pinpoint Booking System plugin up to 2.9.9.6.9.
What is the cause of CVE-2026-15403?
The flaw is a Blind SQL Injection via the 'field' parameter, caused by insufficient escaping of user-supplied input and lack of proper preparation of the existing SQL query.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.