← Vulnerability feed

Vulnerability record · CVE-2020-9372 · published 4 March 2020

CVE-2020-9372: Codepeople appointment booking calendar csv injection vulnerability

Codepeople · Appointment Booking Calendar

The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.

7.8 CVSS 3.1 High EPSS 8.6% · top 5.1% CWE-1236 · CSV injection
7.8CVSS 3.1 base score, v2 6.8
8.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-9372 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-46247Codepeople appointment booking calendar missing authorization vulnerabilityMissing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Accessing Functionality Not Proper…EPSS 0.39%9.8CVE-2016-10916Codepeople appointment booking calendar sql injection vulnerabilityThe appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.EPSS 1.8%8.8CVE-2025-46241Codepeople appointment booking calendar cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows SQL Injection.This iss…EPSS 0.19%8.8CVE-2024-0856Codepeople appointment booking calendar cross-site request forgery vulnerabilityThe Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged …EPSS 0.38%8.8CVE-2022-43482Codepeople appointment booking calendar missing authorization vulnerabilityMissing Authorization vulnerability in Appointment Booking Calendar plugin <= 1.3.69 on WordPress.EPSS 0.54%7.5CVE-2024-12274Codepeople appointment booking calendar vulnerabilityThe Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.1.23 export settings functionality exports data to a public f…EPSS 0.64%7.5CVE-2015-7319Codepeople appointment booking calendar sql injection vulnerabilitySQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPre…EPSS 2.4%6.1CVE-2019-14791Codepeople appointment booking calendar cross-site scripting vulnerabilityThe Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter.EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2020-9372), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.