Sceawere
Vulnerability Detail
CVE-2026-97248UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated PHP Object Injection Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 3h ago
- Vendor
- Booking Activities Team
- Product
- Booking Activities
- Attack Type
- CWE-502 Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-09-30T13:17:36.830Z",
"pubdate": "2026-09-30T13:17:36.830Z",
"executiveSummary": "The Booking Activities plugin for WordPress, specifically versions 1.18.7.1 and earlier, is susceptible to an unauthenticated PHP Object Injection vulnerability. This flaw arises from the improper handling of user-supplied data during the deserialization process. An unauthenticated remote attacker can exploit this vulnerability by injecting a crafted serialized object into the application, potentially leading to arbitrary code execution, unauthorized file operations, or other malicious actions depending on the available gadget chains present in the application's environment. The vulnerability poses a critical risk to the confidentiality, integrity, and availability of the affected WordPress installation. Exploitation does not require prior authentication or elevated privileges, making it highly accessible to remote adversaries. Users are advised to exercise caution and prioritize updating the plugin to a patched version once available to mitigate the risk of compromise.",
"technicalDetails": "The vulnerability is rooted in the insecure use of the PHP unserialize() function on unsanitized user input within the Booking Activities plugin. PHP Object Injection occurs when an application deserializes user-controlled data without adequate validation or integrity checks. By passing a specially crafted serialized string to the vulnerable function, an attacker can manipulate the state of objects within the application's memory space.\nThe attack flow initiates when an unauthenticated attacker transmits a malicious payload via a crafted HTTP request to a vulnerable endpoint within the Booking Activities plugin. Because the input is processed by unserialize() without filtering, the PHP engine instantiates the object represented by the serialized data. If the application environment contains 'gadget chains'—existing classes that perform sensitive operations (e.g., file system access, database queries, or command execution) within their magic methods like __destruct(), __wakeup(), or __toString()—the attacker can orchestrate these chains to achieve arbitrary code execution.\nThe technical impact is significant as it allows the attacker to bypass standard authentication mechanisms and execute operations with the privileges of the web server process. By chaining appropriate classes available within the WordPress core or the plugin's codebase, an adversary can achieve Remote Code Execution (RCE), leading to full site takeover, data exfiltration, or the establishment of persistent backdoors. The vulnerability affects all versions up to and including 1.18.7.1. Since the application fails to validate the structure or origin of the serialized object, the attacker-supplied payload can overwrite existing object properties or trigger unintended behavior in the application logic.\nSuccessful exploitation requires that the target environment contains sufficient PHP classes that can be used to construct a viable gadget chain. While the specific entry point is within the Booking Activities plugin, the broader impact is constrained by the PHP environment's available classes, which often include numerous WordPress core functions and common plugin libraries, significantly increasing the probability of finding a functional exploit vector."
}