MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 6 h ago, last 6 h ago, peak #5

Critical unauthenticated PHP object injection flaw flagged in Booking Activities

Original: ๐Ÿšจ CVE-2026-97248 โ€” CVSS 9.8 CRITICAL Unauthenticated PHP Object Injection in Booking Activities ๐Ÿ”Ž Details: https:// stem

Security researchers are warning about CVE-2026-97248, a critical vulnerability in the Booking Activities plugin rated 9.8 on the CVSS scale. The flaw is an unauthenticated PHP object injection issue, meaning remote attackers could potentially exploit it without any credentials. Details are being circulated in infosec communities as administrators are urged to check their installations and patch promptly.

Why now: A maximum-severity unauthenticated vulnerability affecting a widely used WordPress booking plugin demands immediate attention from site administrators.

Booking ActivitiesCVE-2026-97248

Open on mastodon โ†’

Rank over time, top of the chart is #1. 2 snapshots from 6 h ago to 6 h ago.

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/492028