CRITICAL
9.8 CVE-2026-97248 Published 30 Sept 2026
Booking Activities WordPress Plugin PHP Object Injection Vulnerability
Worried this affects your website?
Booking Activities versions up to and including 1.18.7.1 are affected by an Unauthenticated PHP Object Injection vulnerability.
An attacker can exploit this issue without authentication. The vulnerability is present in all versions up to 1.18.7.1.
Reference: CVE-2026-97248 on NVD
← Back to Security News