Review
Webber Zone
CVE published 2026-07-22
CVE-2026-12987
The Events Manager WordPress plugin before version 7.3.7 is vulnerable to PHP object injection. This is due to the plugin's unsafe handling of booking-registration data when using No-User-Account Booking Mode. Specifically, a booker-supplied registration field is stored as booking meta and later deserialized without proper restrictions on allowed classes. This vulnerability can be exploited to inject mali [truncated]