PT-2022-13906 · WordPress · Booking Calendar

Ramuel Gall

·

Published

2022-05-10

·

Updated

2022-05-17

·

CVE-2022-1463

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Booking Calendar plugin for WordPress version 9.1 and earlier
Description The issue allows for PHP Object Injection via the bookingflextimeline shortcode. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site.
Recommendations For versions up to and including 9.1, update to a version later than 9.1 to resolve the issue. As a temporary workaround, consider restricting access to the bookingflextimeline shortcode until a patch is available.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1463

Affected Products

Booking Calendar