CVE-2026-97248: WordPress Booking Activities plugin <= 1.18.7.1 - PHP Object Injection vulnerability
Published Sep 30, 2026
·Updated
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions.
Affected Software
1 affected component
Booking Activities Booking Activities<=1.18.7.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Booking Activities pluginto a version that resolves this vulnerability.Fixed in 1.18.8
Event History
Sep 30, 2026
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or prior access to the site.
2
Which installations are affected?
Booking Activities versions 1.18.7.1 and earlier are affected.
3
What impact could successful exploitation have?
The supplied severity vector indicates network-reachable exploitation with low attack complexity and potential high impact on confidentiality, integrity, and availability.