{"id":"CVE-2026-91024","title":"The Booking Manager  WordPress plugin before 2.1.21 does not sanitize and escape values taken from a fetched external iCalendar feed before using them in a SQL query, allowing authenticated users with Author-level access and above to per…","summary":"The Booking Manager  WordPress plugin before 2.1.21 does not sanitize and escape values taken from a fetched external iCalendar feed before using them in a SQL query, allowing authenticated users with Author-level access and above to per…","severity":"none","cwe":["CWE-89"],"product":"Booking Manager","affected":["booking_manager < 2.1.21"],"published":"2026-09-23","updated":"2026-09-23","sourceUpdated":"2026-09-23T06:17:05.417","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-91024","references":[{"url":"https://wpscan.com/vulnerability/a5472152-0b96-4fc6-af90-2f1b01811237/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-23T06:17:57.899Z","slug":"CVE-2026-91024","body":"## Overview\n\nThe Booking Manager  WordPress plugin before 2.1.21 does not sanitize and escape values taken from a fetched external iCalendar feed before using them in a SQL query, allowing authenticated users with Author-level access and above to perform SQL injection attacks by importing a feed they control.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}