Appointments <= 2.2.1 - Unauthenticated PHP Object Injection
criticalThe Appointments plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.1 via deserialization of untrusted input from the `wpmudev_appointments` cookie. This allows unauthenticated attackers to inject a PHP Object. Attackers were actively exploiting this vulnerability with the...
- CVSS:
- 9.8
- Affected:
- up to 2.2.2
- Fixed in:
- 2.2.2
- Disclosed:
- Oct 2, 2017