CVE-2014-3210: Dotonpaper Booking System
Medium severity, CVSS 6.5. EPSS: 3.6% chance of exploitation in the next 30 days.
SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the booking_form_id parameter to wp-admin/admin-ajax.php.
Affected products
- Dotonpaper Booking System: up to and including 1.2; version 1.0 only; version 1.1 only
Published 2014-05-22. Last modified 2026-06-17.