PT-2026-56328 · WordPress · Appointment Booking Calendar Plugin+1
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Appointment Booking Calendar Plugin and Scheduling Plugin versions prior to 1.1.29
Description
The plugin fails to validate data before passing it to a PHP deserialization function. This allows unauthenticated attackers to inject arbitrary PHP objects. If a suitable gadget chain (a sequence of existing code fragments that can be executed during deserialization) is present on the site, this can be leveraged to achieve remote code execution.
Recommendations
Update the plugin to version 1.1.29 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Appointment Booking Calendar Plugin
Scheduling Plugin