Impact
The identified vulnerability is an unauthenticated PHP Object Injection in the Appointment Booking Calendar and Scheduling Plugin up to version 1.1.28. Because the plugin forwards unserialized data directly to the PHP deserialize function, attackers can embed malicious objects. When a suitable gadget chain exists on the same WordPress installation, this flaw can lead to remote code execution, compromising confidentiality, integrity, and availability of the entire site.
Affected Systems
WordPress sites that have either the Appointment Booking Calendar or Scheduling Plugin installed at versions 1.1.28 or earlier are affected. Any site hosting either plugin in those versions is susceptible to the exploitation described.
Risk and Exploitability
The CVSS base score of 8.1 signals a high‑severity vulnerability, and the EPSS score of <1% suggests limited current exploitation activity. The flaw can be triggered from a remote source without authentication; an attacker can craft and send a serialized payload to the plugin’s endpoint, and if a gadget chain is available, achieve remote code execution. The vulnerability is not listed in the CISA KEV catalog, but its impact remains the same.
OpenCVE Enrichment