The Booking Package plugin for WordPress is vulnerable to SQL Injection via the 'email' form parameter in versions up to and including 1.7.20. This vulnerability allows unauthenticated attackers to append additional SQL queries to existing queries, potentially extracting sensitive information from the database. The vulnerability exists in the /wp-json/booking-package/v1/request REST API endpoint, which is [truncated]
CVE-2026-9851 is a high-severity vulnerability in the Booking Package plugin for WordPress. The plugin is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is due to a missing capability check on the 'updateUser' branch of the package_app_action AJAX endpoint. The handler only validates a nonce and the dispatcher invokes Schedule::updateUser() with the [truncated]