CRITICAL
9.3 CVE-2026-39764 Published 6 Oct 2026
Unauthenticated SQL Injection in Radius Booking Plugin
Worried this affects your website?
An SQL Injection vulnerability has been discovered in Radius Booking — Booking Calendar for Appointments & Services.
The flaw affects plugin versions 1.0.19 and earlier and can be exploited without authentication.
Reference: CVE-2026-39764 on NVD
← Back to Security News