Booking Calendar < 3.2.2 - Unauthenticated Arbitrary File Upload
85Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9.8epss 4.5%
from disclosure to weapon
Published on NVDDec 12
VulnCheck+376d
exploitation probability
4.5%top 9% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · Booking calendar, Appointment Booking Systempublic PoCs found — 1
cve_referencewpscan.com/vulnerability/4d91f3e1-4de9-46c1-b5ba-cc55b7726867unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.