PT-2024-38096 · WordPress · The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin

Jeewan Kumar Bhatta

·

Published

2024-09-12

·

Updated

2025-09-15

·

CVE-2024-7129

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin version 1.6.7.42 and earlier
Description The issue is related to the failure to escape template syntax provided via user input, leading to Twig Template Injection. This can be further exploited to result in remote code execution by high-privilege users such as admins.
Recommendations For versions prior to 1.6.7.43, update to version 1.6.7.43 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's template syntax functionality to minimize the risk of exploitation.

Exploit

Fix

Related Identifiers

CVE-2024-7129

Affected Products

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin