CVE · High

CVE-2022-1463 — Booking Calendar [booking] < 9.1.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-1463 Booking Calendar [booking] < 9.1.1 Deserialization of Untrusted Data High 8.8 < 9.1.1 9.1.1 2022-04-18

CVE-2022-1463

The Booking Calendar plugin before version 9.1.1 contains a PHP object injection vulnerability because it deserializes user-controlled data without proper validation. Unauthenticated users can exploit this flaw if a timeline is publicly published, while authenticated users can exploit it regardless of timeline visibility. A successful attack would require a compatible POP chain, potentially sourced from another installed plugin, to execute arbitrary code.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.