CVE-2017-20243: Quanticalabs Car Park Booking System
High severity, CVSS 8.2. EPSS: 0.3% chance of exploitation in the next 30 days.
WordPress Car Park Booking Plugin version 13 October 17 contains a time-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the space_id parameter. Attackers can send GET requests to the booking-page endpoint with malicious space_id values using AND SLEEP() payloads to extract sensitive database information.
Affected products
- Quanticalabs Car Park Booking System: version 1.0 only
Published 2026-06-09. Last modified 2026-07-21.