PT-2024-38096 · WordPress · The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin

·

CVE-2024-7129

·

Published

2024-09-12

·

Updated

2025-09-15

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin version 1.6.7.42 and earlier
Description The issue is related to the failure to escape template syntax provided via user input, leading to Twig Template Injection. This can be further exploited to result in remote code execution by high-privilege users such as admins.
Recommendations For versions prior to 1.6.7.43, update to version 1.6.7.43 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's template syntax functionality to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2024-7129

Affected Products

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin