First published: Tue May 10 2022(Updated: )
The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Booking Calendar | <=9.1 |
Update to version 9.1.1, or newer.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-1463 is considered high due to the possibility of PHP Object Injection vulnerabilities.
To fix CVE-2022-1463, update the Booking Calendar plugin to version 9.2 or later.
CVE-2022-1463 can be exploited by subscriber-level users and above on a vulnerable site.
The affected versions of the Booking Calendar plugin are up to and including version 9.1.
CVE-2022-1463 is a PHP Object Injection vulnerability associated with the [bookingflextimeline] shortcode.