{"api_version":"1","generated_at":"2026-07-23T19:55:30+00:00","cve":"CVE-2020-9372","urls":{"html":"https://cve.report/CVE-2020-9372","api":"https://cve.report/api/cve/CVE-2020-9372.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-9372","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-9372"},"summary":{"title":"CVE-2020-9372","description":"The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-03-04 19:15:00","updated_at":"2022-01-01 19:35:00"},"problem_types":["CWE-1236"],"metrics":[],"references":[{"url":"http://packetstormsecurity.com/files/156694/WordPress-Appointment-Booking-Calendar-1.3.34-CSV-Injection.html","name":"http://packetstormsecurity.com/files/156694/WordPress-Appointment-Booking-Calendar-1.3.34-CSV-Injection.html","refsource":"MISC","tags":[],"title":"WordPress Appointment Booking Calendar 1.3.34 CSV Injection ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://drive.google.com/open?id=1NNcYPaJir9SleyVr4cSPqpI2LNM7rtx9","name":"https://drive.google.com/open?id=1NNcYPaJir9SleyVr4cSPqpI2LNM7rtx9","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"appointment_booking_calendar - Google Drive","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.hotdreamweaver.com/support/view.php?id=815925","name":"https://www.hotdreamweaver.com/support/view.php?id=815925","refsource":"MISC","tags":["Permissions Required"],"title":"Plugins and Extensions Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://wordpress.org/plugins/appointment-booking-calendar/#developers","name":"https://wordpress.org/plugins/appointment-booking-calendar/#developers","refsource":"MISC","tags":["Release Notes"],"title":"WordPress › Appointment Booking Calendar « WordPress Plugins","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-9372","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-9372","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"9372","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"codepeople","cpe5":"appointment_booking_calendar","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"9372","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"codepeople","cpe5":"appointment_booking_calendar","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-9372","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://wordpress.org/plugins/appointment-booking-calendar/#developers","refsource":"MISC","name":"https://wordpress.org/plugins/appointment-booking-calendar/#developers"},{"refsource":"MISC","name":"https://drive.google.com/open?id=1NNcYPaJir9SleyVr4cSPqpI2LNM7rtx9","url":"https://drive.google.com/open?id=1NNcYPaJir9SleyVr4cSPqpI2LNM7rtx9"},{"refsource":"MISC","name":"https://www.hotdreamweaver.com/support/view.php?id=815925","url":"https://www.hotdreamweaver.com/support/view.php?id=815925"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/156694/WordPress-Appointment-Booking-Calendar-1.3.34-CSV-Injection.html","url":"http://packetstormsecurity.com/files/156694/WordPress-Appointment-Booking-Calendar-1.3.34-CSV-Injection.html"}]}},"nvd":{"publishedDate":"2020-03-04 19:15:00","lastModifiedDate":"2022-01-01 19:35:00","problem_types":["CWE-1236"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:codepeople:appointment_booking_calendar:*:*:*:*:*:wordpress:*:*","versionEndExcluding":"1.3.35","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"9372","Ordinal":"169758","Title":"CVE-2020-9372","CVE":"CVE-2020-9372","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"9372","Ordinal":"1","NoteData":"The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"9372","Ordinal":"2","NoteData":"2020-03-04","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"9372","Ordinal":"3","NoteData":"2020-03-12","Type":"Other","Title":"Modified"}]}}}