Impact
The vulnerability is an unauthenticated PHP Object Injection in versions of the Booking Activities plugin for WordPress. The flaw allows an attacker to inject arbitrary serialized objects into the application, leading to remote code execution. It is a classic PHP deserialization flaw identified as CWE‑502. Because the plugin accepts unsanitized input for object serialization, an attacker can execute arbitrary PHP code on the host.
Affected Systems
The affected product is the Booking Activities plugin for WordPress versions up through 1.18.7.1, maintained by the Booking Activities Team. Sites running any of those releases are vulnerable.
Risk and Exploitability
The CVSS base score is 9.8, indicating critical severity and a high likelihood that the flaw could be exploited if present. The EPSS score is unavailable, but the unauthenticated nature and the absence of a public exploit report do not reduce risk. The vulnerability is not listed in the CISA KEV catalog, yet the high CVSS rating and potential for remote code execution make it a top priority for remediation. The attack vector is likely via a crafted payload delivered to a public endpoint that accepts serialized data or through the booking interface, enabling an attacker to deliver malicious objects without authentication.
OpenCVE Enrichment