Security Advisory

CVE-2026-12378

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-08 06:00:01
Last updated 2026-07-08 10:04:03
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to achieve remote code execution.