CVE-2022-1463: Booking Calendar <= 9.1 - PHP Object Injection via Shortcode
Published May 10, 2022
·Updated
The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site.
Affected Software
1 affected component
Booking Calendar Project Booking Calendar Wordpress<=9.1
Remediation
Information
Update to version 9.1.1, or newer.
Event History
May 10, 2022
CVE Published
via MITRE·07:37 PM
Data Sourced
via MITRE·07:37 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1463?
The severity of CVE-2022-1463 is considered high due to the possibility of PHP Object Injection vulnerabilities.
2
How do I fix CVE-2022-1463?
To fix CVE-2022-1463, update the Booking Calendar plugin to version 9.2 or later.
3
Who can exploit CVE-2022-1463?
CVE-2022-1463 can be exploited by subscriber-level users and above on a vulnerable site.
4
Which versions of the Booking Calendar plugin are affected by CVE-2022-1463?
The affected versions of the Booking Calendar plugin are up to and including version 9.1.
5
What kind of vulnerability is CVE-2022-1463?
CVE-2022-1463 is a PHP Object Injection vulnerability associated with the [bookingflextimeline] shortcode.