Description
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to achieve remote code execution.
Published: 2026-07-08
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The identified vulnerability is an unauthenticated PHP Object Injection in the Appointment Booking Calendar and Scheduling Plugin up to version 1.1.28. Because the plugin forwards unserialized data directly to the PHP deserialize function, attackers can embed malicious objects. When a suitable gadget chain exists on the same WordPress installation, this flaw can lead to remote code execution, compromising confidentiality, integrity, and availability of the entire site.

Affected Systems

WordPress sites that have either the Appointment Booking Calendar or Scheduling Plugin installed at versions 1.1.28 or earlier are affected. Any site hosting either plugin in those versions is susceptible to the exploitation described.

Risk and Exploitability

The CVSS base score of 8.1 signals a high‑severity vulnerability, and the EPSS score of <1% suggests limited current exploitation activity. The flaw can be triggered from a remote source without authentication; an attacker can craft and send a serialized payload to the plugin’s endpoint, and if a gadget chain is available, achieve remote code execution. The vulnerability is not listed in the CISA KEV catalog, but its impact remains the same.

Generated by OpenCVE AI on July 26, 2026 at 18:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Appointment Booking Calendar or Scheduling Plugin to the latest version that validates serialized data and protect the site or uninstall the vulnerable plugin until a secure version is available.
  • Implement web‑application firewall rules or request sanitization filters that block serialized PHP data in requests targeting the plugin’s endpoints to reduce the risk of successful injection.
  • Enable a custom input validation routine that inspects incoming request data for serialized payloads and rejects them before reaching the plugin to further mitigate potential exploitation.

Generated by OpenCVE AI on July 26, 2026 at 18:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502

Wed, 22 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502

Tue, 21 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502

Thu, 16 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502

Wed, 15 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502

Mon, 13 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502

Sun, 12 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502

Sat, 11 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502

Fri, 10 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502

Fri, 10 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502

Thu, 09 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502

Wed, 08 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502

Wed, 08 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to achieve remote code execution.
Title BookingPress <= 1.1.28 - Unauthenticated PHP Object Injection
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-08T10:04:03.242Z

Reserved: 2026-06-16T08:51:08.047Z

Link: CVE-2026-12378

cve-icon Vulnrichment

Updated: 2026-07-08T10:03:16.422Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T18:30:04Z

Weaknesses

No weakness.