SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-9372

The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in…

HIGH 7.8EPSS 8.61%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (8.61%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
8.61% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-1236
Affected
codepeople/appointment booking calendar
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.