The plugin does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injection.
View the template here CVE-2022-0658.yaml
References:
https://wordpress.org/plugins/commonsbooking/