High severity8.1NVD Advisory· Published Jul 8, 2026· Updated Jul 8, 2026
CVE-2026-12378
CVE-2026-12378
Description
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to achieve remote code execution.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.