VYPR
Unrated severityNVD Advisory· Published Jul 8, 2026· Updated Jul 8, 2026

BookingPress <= 1.1.28 - Unauthenticated PHP Object Injection

CVE-2026-12378

Description

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to achieve remote code execution.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.