The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-User-Account Booking Mode: a booker-supplied registration field is stored as booking meta and later deserialized without restricting allowed classes, enabling PHP object injection. The resulting gadget chain reaches a database query that is built without parameterisation, so an unauthenticated attacker can read arbitrary database data (e.g. user password hashes, secret keys) when the booking is later loaded.
We have discovered 32,860 live websites that are affected by CVE-2026-12987.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 32,860 live websites (92% of Events Manager for WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 100 versions ( 93% of all versions) |
| 8,750 websites | |
| 7,150 websites | |
| 2,510 websites | |
| 1,711 websites | |
| 1,643 websites | |
| 1,350 websites | |
| 964 websites | |
| 803 websites | |
| 657 websites | |
| 646 websites |
| .com | 7,882 websites |
| .de | 5,587 websites |
| .org | 4,677 websites |
| .nl | 1,615 websites |
| .fr | 1,302 websites |
| .it | 1,044 websites |
| .ch | 839 websites |
| .co.uk | 721 websites |
| .net | 652 websites |
| .at | 575 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **************.org | **,*** | ||
| ****.org | **,*** | ||
| *********.*******.org | **,*** | ||
| **************.gov | **,*** | ||
| ********.org | **,*** | ||
| *****.br | **,*** | ||
| ****.org | **,*** | ||
| *****.org | **,*** | ||
| ***************.it | **,*** | ||
| ***********.*****.gov | **,*** |
FAQ