ZeroHour

CVE-2024-7129

PoC
CVSS 3.1
7.2 high
EPSS
1%p65
Published
()
Modified
Description

The Appointment Booking Calendar WordPress plugin before 1.6.7.43 does not escape template syntax provided via user input, leading to Twig Template Injection which further exploited can result to remote code Execution by high privilege such as admins

Vendors
nsqua
Products
simply schedule appointments
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.