CVE-2026-27095: WordPress Bus Ticket Booking with Seat Reservation plugin <= 5.6.0 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Object Injection.This issue affects Bus Ticket Booking with Seat Reservation: from n/a through <= 5.6.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27095?
CVE-2026-27095 is classified as a critical severity vulnerability due to its potential for PHP Object Injection and deserialization of untrusted data.
How do I fix CVE-2026-27095?
To fix CVE-2026-27095, update the Bus Ticket Booking with Seat Reservation plugin to version 5.6.1 or higher.
What systems are affected by CVE-2026-27095?
CVE-2026-27095 affects the MagePeopleTeam Bus Ticket Booking with Seat Reservation WordPress plugin versions up to and including 5.6.0.
What impact does CVE-2026-27095 have on my website?
CVE-2026-27095 can allow attackers to execute arbitrary PHP code through PHP Object Injection, compromising website security.
Where can I find more information about CVE-2026-27095?
For detailed information about CVE-2026-27095, refer to security reports and vulnerability databases that track WordPress plugin vulnerabilities.