CVE-2026-12378
Unknown Appointment Booking Calendar Plugin and Scheduling Plugin 취약점
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to achieve remote code execution.
- 대응 우선순위
- 점검
- CVSS
- 8.1
- EPSS
- 0.39% 백분위 31.7% · 2026.08.03 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.07.08