CVE-2026-12378
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a
CVSS
8.1
Alto
EPSS
0.4%
p31
KEV
—
Exploit Today
9
0-100
Publicado: 8 jul 2026 · Última mod.: 8 jul 2026
0.2%EPSS · 30 días0.4%
2026-07-082026-07-21
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to achieve remote code execution.
Sin CVEs relacionados por CWE o producto.