search
CVE-2026-97248
Trends
- 1Critical unauthenticated PHP object injection flaw flagged in Booking Activities▼🚨 CVE-2026-97248 — CVSS 9.8 CRITICAL Unauthenticated PHP Object Injection in Booking Activities 🔎 Details: https:// stem
Security researchers are warning about CVE-2026-97248, a critical vulnerability in the Booking Activities plugin rated 9.8 on the CVSS scale. The flaw is an unauthenticated PHP object injection issue, meaning remote attackers could potentially exploit it without any credentials. Details are being circulated in infosec communities as administrators are urged to check their installations and patch promptly.