"product_name":"BookingPress – Appointments Booking Calendar Plugin and Online Scheduling Plugin",
"version":{
"version_data":[
{
"version_affected":"<",
"version_name":"1.0.11",
"version_value":"1.0.11"
}
]
}
}
]
}
}
]
}
},
"description":{
"description_data":[
{
"lang":"eng",
"value":"The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query via the bookingpress_front_get_category_services AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection"