8.8

CVE-2022-1463

Exploit

Booking Calendar <= 9.1 - PHP Object Injection via Shortcode

Booking Calendar <= 9.1 - PHP Object Injection via Shortcode

The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site.
Mögliche Gegenmaßnahme
Booking Calendar: Update to version 9.1.1, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Booking Calendar ProjectBooking Calendar SwPlatformwordpress Version <= 9.1
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Booking Calendar
Version *-9.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.67% 0.738
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
security@wordfence.com 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

https://www.wordfence.com/blog/2022/04/php-object-injection-in-booking-calendar-plugin/
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/55491c64-e4b5-4919-bdcb-7285f2a3c3cd
Third Party Advisory