CRITICAL 9.3 CVE-2026-39764 Published 6 Oct 2026

Unauthenticated SQL Injection in Radius Booking Plugin

Worried this affects your website?

An SQL Injection vulnerability has been discovered in Radius Booking — Booking Calendar for Appointments & Services.

The flaw affects plugin versions 1.0.19 and earlier and can be exploited without authentication.

Reference: CVE-2026-39764 on NVD

← Back to Security News