Impact
The Booking Activities plugin is vulnerable to unauthenticated PHP Object Injection in all releases up to and including version 1.18.4. Attackers can exploit the flaw by supplying crafted input that causes PHP to instantiate arbitrary objects, potentially leading to the execution of malicious code and complete compromise of the affected WordPress site.
Affected Systems
All users of the Booking Activities plugin owned by the Booking Activities Team whose implementations are 1.18.4 or earlier are impacted. Any WordPress installation that has the plugin installed without updating past this version is at risk.
Risk and Exploitability
The flaw carries a CVSS score of 8.8, indicating high severity, and despite the lack of an EPSS value and no listing in the CISA KEV catalog, the unauthenticated nature of the attack vector means that exploitation could be attempted by anyone with network access to the WordPress site. An attacker would only need to send a crafted HTTP request that triggers object deserialization, making the vulnerability feasible and dangerous for exposed sites.
OpenCVE Enrichment