← WordPress Vulnerabilities
WordPress security by component

Directorist Booking

Directorist Booking is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jun 17, 2026; the highest published CVSS base score is 9.3.

Plugin slug: directorist-booking

CVE-2026-49073: Directorist Booking: SQL injection

Directorist Booking is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 3.0.3. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedJun 17, 2026
Known safe version3.0.4
Published vulnerabilities for directorist-booking
Safe version
Jun 17, 2026 CVE-2026-49073
Directorist Booking: SQL injection
Directorist Booking is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 3.0.3. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
3.0.4
CVE8.5
NVDPending
Apr 27, 2026 CVE-2026-22336
Directorist Booking: SQL injection
Directorist Booking is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a to < 3.0.2. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
3.0.2
CVE9.3
NVDPending