Wordpress Alert: SQL injection in booking plugins

A booking search or calendar parameter reaches an unsafe query. Reservation and customer data may be exposed.

What it looks like

A booking search or calendar parameter reaches an unsafe query.

Why it matters

Reservation and customer data may be exposed.

What to check

Check the installed booking plugin's advisories and query handling.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP SQL injection prevention.