Booking Calendar <= 9.1 - PHP Object Injection via Shortcode
2022-04-18 00:00
RamStrategic Overview
StatusPatched in 9.1.1
Affected PluginBooking Calendar
Affected Version
<= 9.1CVSS8.5High
CVE
CVE-2022-1463Vulnerability Overview
The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site.
Technical Analysis
REMEDIATION: Update to version 9.1.1, or a newer patched version --- IDENTIFIER: CWE-502 (Deserialization of Untrusted Data) The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C