Security Advisory

CVE-2024-12274

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-01-13 06:00:01
Last updated 2025-08-27 12:00:25
Assigner WPScan
State PUBLISHED

Description

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.1.23 export settings functionality exports data to a public folder, with an easily guessable file name, allowing unauthenticated attackers to access the exported files (if they exist).