Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High2
Medium0
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2026-07-08

CVE-2026-12378 - Appointment Booking Calendar Plugin and Scheduling Plugin

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to achieve remote code execution.

PLUGIN Appointment Booking Calendar Plugin and Scheduling Plugin

CVE-2026-12378

HIGH CVSS 8.1 2026-07-08
Threat Entry Updated 2025-05-08

CVE-2024-12274 - Appointment Booking Calendar Plugin And Scheduling

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.1.23 export settings functionality exports data to a public folder, with an easily guessable file name, allowing unauthenticated attackers to access the exported files (if they exist).

PLUGIN Appointment Booking Calendar Plugin And Scheduling

CVE-2024-12274

HIGH CVSS 7.5 2025-01-13
Scroll to top