Booking Calendar <= 9.1 - PHP Object Injection via Shortcode

2022-04-18 00:00
Ram

Strategic Overview

Status
Patched in 9.1.1
Affected PluginBooking Calendar
Affected Version<= 9.1
CVSS8.5High
CVECVE-2022-1463
View all Booking Calendar vulnerabilities

Vulnerability Overview

The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site.

Technical Analysis

REMEDIATION: Update to version 9.1.1, or a newer patched version --- IDENTIFIER: CWE-502 (Deserialization of Untrusted Data) The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C