CVE-2022-1463: Booking Calendar Project Booking Calendar

High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.

The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site.

Affected products

Published 2022-05-10. Last modified 2026-06-17.