Security Advisory
CVE-2026-12378
8.1
HIGH
Vulnerability Description
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to achieve remote code execution.
Published Date
July 8, 2026
Official Source
NIST NVD Advisory