Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-1463
HistoryMay 10, 2022 - 8:15 p.m.

Design/Logic Flaw

2022-05-1020:15:00
PRIOn knowledge base
www.prio-n.com
2

8.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.1%

The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site.

CPENameOperatorVersion
booking_calendarle9.1

8.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.1%