# CVE-2022-0739-Exploitation
An exploitation of CVE-2022-0739.
It about BookingPress WordPress plugin before 1.0.11.
By using bookingpress_front_get_category_services AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection.
Since the plugin fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view