PatchSiren

Webber Zone CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Webber Zone CVE published 2026-07-22

CVE-2026-12987

The Events Manager WordPress plugin before version 7.3.7 is vulnerable to PHP object injection. This is due to the plugin's unsafe handling of booking-registration data when using No-User-Account Booking Mode. Specifically, a booker-supplied registration field is stored as booking meta and later deserialized without proper restrictions on allowed classes. This vulnerability can be exploited to inject mali [truncated]