Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-39764: Radius Booking plugin can let attackers read or change data

CVE-2026-39764 · published 4 days ago
Summary

The Radius Booking – Booking Calendar for Appointments & Services plugin for WordPress (versions up to 1.0.19) lets anyone on the internet send specially crafted requests that cause the website’s database to run unintended commands. This could expose private information or let an attacker alter booking records. Upgrade the plugin to the latest version or apply the vendor’s patch as soon as possible.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
radiustheme radius booking — booking calendar for appointments &amp; services <= 1.0.19
Original advisory text
WordPress Radius Booking — Booking Calendar for Appointments & Services plugin <= 1.0.19 - SQL Injection vulnerability
Unauthenticated SQL Injection in Radius Booking — Booking Calendar for Appointments &amp; Services <= 1.0.19 versions.
Fix within
Internet-facing 14 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker partial control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-89SQL Injection
Timeline
Published6 Oct 2026
Updated7 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-39764 · MITRE
Track software like this
Free during beta