CVE-2026-12378
Appointment Booking Calendar Plugin and Scheduling Plugin
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to achieve remote code execution.
- CVSS
- 8.1
- EPSS
- 0.39% 31.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.08