Security Advisory

CVE-2026-12378

8.1
HIGH

Vulnerability Description

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to achieve remote code execution.
Published Date July 8, 2026
Official Source NIST NVD Advisory