CVE-2026-13395: Unknown Online Scheduling And Appointment Booking System

High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.

The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data such as password hashes from the database.

Affected products

  • Unknown Online Scheduling And Appointment Booking System: before 27.8 (fixed in 27.8)

Published 2026-07-30. Last modified 2026-07-30.