CVE-2026-12378: BookingPress <= 1.1.28 - Unauthenticated PHP Object Injection
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to achieve remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12378?
CVE-2026-12378 has a severity rating of high, with a CVSS score of 8.1.
How do I fix CVE-2026-12378?
To address CVE-2026-12378, you should immediately update the BookingPress plugin to the latest version that is not affected by this vulnerability.
What systems are affected by CVE-2026-12378?
CVE-2026-12378 affects versions of the BookingPress plugin (Appointment Booking Calendar Plugin and Scheduling Plugin) up to and including 1.1.28.
Who can exploit CVE-2026-12378?
CVE-2026-12378 can be exploited by unauthenticated attackers, as it does not require user authentication to execute.
What type of vulnerability is CVE-2026-12378?
CVE-2026-12378 is an unauthenticated PHP Object Injection vulnerability that occurs due to improper data validation.