CVE-2015-9460: Pinpoint Booking System
High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.
The booking-system plugin before 2.1 for WordPress has DOPBSPBackEndTranslation::display SQL injection via the language parameter.
Affected products
- Pinpoint Pinpoint Booking System: before 2.1 (fixed in 2.1)
Published 2019-10-10. Last modified 2026-06-17.