CVE-2022-1463
The Booking Calendar plugin before version 9.1.1 contains a PHP object injection vulnerability because it deserializes user-controlled data without proper validation. Unauthenticated users can exploit this flaw if a timeline is publicly published, while authenticated users can exploit it regardless of timeline visibility. A successful attack would require a compatible POP chain, potentially sourced from another installed plugin, to execute arbitrary code.
Based on public CVE data (MITRE/NVD).