Unrated severityNVD Advisory· Published May 10, 2022· Updated Feb 13, 2025
Booking Calendar <= 9.1 - PHP Object Injection via Shortcode
CVE-2022-1463
Description
The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site.
Affected products
2- Range: <=9.1
- wpdevelop/Booking Calendarv5Range: 9.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.wordfence.com/blog/2022/04/php-object-injection-in-booking-calendar-plugin/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.