CVE-2022-1463

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
10/05/2022
Last modified:
17/05/2022

Description

The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:booking_calendar_project:booking_calendar:*:*:*:*:*:wordpress:*:* 9.1 (including)