CVE-2022-1463: Booking Calendar Project Booking Calendar
High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.
The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site.
Affected products
- Booking Calendar Project Booking Calendar: up to and including 9.1
Published 2022-05-10. Last modified 2026-06-17.