CVE-2024-12274 affects the Appointment Booking Calendar and Scheduling Plugin for WordPress prior to version 1.1.23, allowing unauthenticated attackers to access sensitive exported settings files due to predictable filenames and public folder storage. With a CVSS score of 7.5 (High), this vulnerability presents a low-complexity network-based attack that could lead to full confidentiality compromise. While no public exploits, Metasploit modules, or KEV catalog entries exist, and community discussion is minimal, organizations should nonetheless prioritize patching to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.23CPE matchmatch criteria | cpe:2.3:a:codepeople:appointment_booking_calendar:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.