CVE-2026-12378: Unknown Appointment Booking Calendar Plugin And Scheduling Plugin
High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to achieve remote code execution.
Affected products
- Unknown Appointment Booking Calendar Plugin And Scheduling Plugin: up to and including 1.1.28
Published 2026-07-08. Last modified 2026-07-08.