Joomla
iCagenda extension for Joomla
iCagenda is vulnerable to an unrestricted file upload flaw, allowing unauthenticated attackers to execute arbitrary code on the server.
2026-07-11
Description
iCagenda is vulnerable to an unrestricted file upload flaw, allowing unauthenticated attackers to execute arbitrary code on the server.
AI Analyst Comment
Remediation
Actively exploited in the wild (CISA KEV). Apply vendor updates or mitigations promptly.
CISA KEV Details
Deadline: July 13, 2026
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
---METADATA---
VENDOR: wpWax
PRODUCT: Directorist Booking
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
A blind SQL injection vulnerability in the wpWax Directorist Booking plugin allows authenticated users to exfiltrate database information.
Executive Summary:
The Directorist Booking plugin contains a critical blind SQL injection vulnerability that allows authenticated attackers to perform unauthorized database queries.
Vulnerability Details
CVE-ID: CVE-2026-49073
Affected Software: wpWax Directorist Booking
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: This flaw stems from insufficient neutralization of user-supplied input within the plugin's booking functionality. Authenticated users can execute blind SQL injection attacks, potentially leading to the extraction of sensitive data from the database.
Business Impact
With a CVSS score of 8.5, this vulnerability represents a high risk to business operations. Exploitation could result in the theft of proprietary business data, customer booking information, or other sensitive records, leading to significant reputational and operational damage.
Remediation Plan
Immediate Action: Update the Directorist Booking plugin to the latest patched version released by wpWax.
Proactive Monitoring: Review database access logs for unusual, high-frequency query patterns that may indicate automated data exfiltration attempts.
Compensating Controls: Implement WAF filtering to intercept and block SQL injection payloads targeting the application's booking endpoints.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of June 18, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
Administrators must treat this vulnerability with high urgency. Applying the provided vendor update is the only definitive way to remediate the flaw and protect against potential data exfiltration by authenticated users.