Unrated severityNVD Advisory· Published Jul 8, 2026· Updated Jul 8, 2026
BookingPress <= 1.1.28 - Unauthenticated PHP Object Injection
CVE-2026-12378
Description
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to achieve remote code execution.
Affected products
1Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/eb3abb88-43c3-42a8-a8a8-2ad67d37e020/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.