External risk intelligence

Booking Activities Plugin PHP Object Injection

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-97248

The vulnerability affects a WordPress booking plugin. Such plugins are typically deployed as public-facing web components to allow users to interact with scheduling, calendars, and reservation systems directly over the internet.

Deserialization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An unauthenticated PHP Object Injection vulnerability has been identified in a booking plugin, potentially impacting systems that handle user interactions with scheduling and reservation functions. This issue allows for the injection of malicious code without requiring user authentication, which could have broad implications for the integrity and availability of affected systems. The primary concern is to confirm if this specific plugin is in use and assess any potential exposure.

  • Unauthenticated code injection in a booking plugin.
  • Critical severity, public-facing web component.
  • Confirm relevance and exposure for business systems.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted data over the internet to a website using the affected booking plugin. This injection targets how the plugin handles PHP objects, potentially leading to serious security compromises on the server.

  • No authentication or privileges required.
  • Specially crafted data sent to the plugin.
  • Complete server takeover possible.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated PHP Object Injection in Booking Activities could allow an unauthenticated attacker to execute arbitrary code on the server, impacting the integrity and availability of the affected system. This vulnerability may be exploitable when the plugin is used in its intended, public-facing capacity.

  • System code and data integrity.
  • Remote injection via unauthenticated requests.
  • System compromise and denial of service.

Operational Fix

Recommended remediation, mitigation, and detection steps

This unauthenticated PHP object injection vulnerability in Booking Activities could allow attackers to inject malicious code, impacting the confidentiality, integrity, and availability of your systems. The first step is to identify all instances of this plugin, determine their exposure (especially public-facing ones), and confirm business criticality to prioritize remediation efforts. Collaboration between application owners, infrastructure, and security teams will be crucial for a coordinated response.

  • Application owners should prioritize remediation.
  • Verify plugin exposure and business criticality.
  • Plan and coordinate mitigation actions.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Booking Activities plugin?

Booking Activities is a WordPress plugin designed to manage scheduling, reservations, and appointment calendars. It serves as an interactive web component that allows site visitors to book services directly through a browser, acting as the interface between your business operations and the public.

What does PHP Object Injection mean in CVE-2026-97248?

This vulnerability, classified as CWE-502 (Deserialization of Untrusted Data), occurs when the plugin improperly handles serialized data. An attacker can manipulate this data to inject unauthorized PHP objects, which, when processed by the application, can lead to arbitrary code execution on the underlying server.

Do I need to be logged in for an attacker to trigger this?

No, authentication is not required to trigger this vulnerability. The flaw allows an unauthenticated user to send specially crafted data to the plugin. Note that simply visiting the site or viewing a calendar does not trigger the bug; it requires the submission of specifically malicious payloads designed to exploit the deserialization process.

How does Halo Surface Signal categorize this threat?

Halo Surface Signal identifies this as a 'Likely' risk because the affected technology is fundamentally designed to be internet-facing. Since the plugin is meant for public scheduling and reservation tasks, it is almost always exposed to the internet, making it reachable by remote attackers without further internal network access.

When should I take action for this plugin?

You should prioritize this immediately if you use Booking Activities versions 1.18.7.1 or earlier. Start by identifying all web instances where the plugin is active, especially those accessible to the public, and coordinate with your application and security teams to restrict access or apply available vendor updates to mitigate the risk of server compromise.

References