Description
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.
Published: 2026-08-13
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Booking Activities plugin is vulnerable to unauthenticated PHP Object Injection in all releases up to and including version 1.18.4. Attackers can exploit the flaw by supplying crafted input that causes PHP to instantiate arbitrary objects, potentially leading to the execution of malicious code and complete compromise of the affected WordPress site.

Affected Systems

All users of the Booking Activities plugin owned by the Booking Activities Team whose implementations are 1.18.4 or earlier are impacted. Any WordPress installation that has the plugin installed without updating past this version is at risk.

Risk and Exploitability

The flaw carries a CVSS score of 8.8, indicating high severity, and despite the lack of an EPSS value and no listing in the CISA KEV catalog, the unauthenticated nature of the attack vector means that exploitation could be attempted by anyone with network access to the WordPress site. An attacker would only need to send a crafted HTTP request that triggers object deserialization, making the vulnerability feasible and dangerous for exposed sites.

Generated by OpenCVE AI on August 13, 2026 at 15:59 UTC.

Remediation

Vendor Solution

Update the WordPress Booking Activities plugin to the latest available version (at least 1.18.5).


OpenCVE Recommended Actions

  • Update the WordPress Booking Activities plugin to version 1.18.5 or later.
  • If updating immediately is not possible, temporarily deactivate or remove the plugin from the WordPress installation.
  • Apply network filtering to block known malicious traffic patterns targeting the plugin’s vulnerable endpoints while monitoring for suspicious requests.

Generated by OpenCVE AI on August 13, 2026 at 15:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Booking Activities Team
Booking Activities Team booking Activities
Wordpress
Wordpress wordpress
Vendors & Products Booking Activities Team
Booking Activities Team booking Activities
Wordpress
Wordpress wordpress

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.
Title WordPress Booking Activities plugin <= 1.18.4 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Booking Activities Team Booking Activities
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:19:08.760Z

Reserved: 2026-02-25T12:14:40.739Z

Link: CVE-2026-28176

cve-icon Vulnrichment

Updated: 2026-08-13T15:19:02.962Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T14:16:59.663

Modified: 2026-08-14T19:09:20.713

Link: CVE-2026-28176

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T16:45:04Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data