CVE-2026-28176

WordPress Booking Activities plugin <= 1.18.4 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.


We have discovered 1,276 live websites that are affected by CVE-2026-28176.

Run a Free Instant Scan




Affected Software

Product  Booking Activities
Category Wordpress Plugins
Vulnerable Domains1,276 live websites (100% of Booking Activities install base)
Vulnerable Versions
  • from 0 through 1.18.4
Vulnerable Versions Count77 versions ( 99% of all versions)


Common Weakness Enumeration

CWE-502 Deserialization of Untrusted Data



Details

  • Published - Aug 13, 2026
  • Updated - Aug 13, 2026

Credits

  • Taylsec | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-28176
United States90 websites



France532 websites
Germany115 websites
Switzerland69 websites
GB56 websites
Netherlands49 websites
Italy43 websites
Spain34 websites
Czech Republic27 websites
Belgium25 websites

Website Distribution by TLD

Number of websites using CVE-2026-28176
.com372 websites
.fr290 websites
.org73 websites
.de72 websites
.ch50 websites
.nl45 websites
.co.uk39 websites
.be29 websites
.it29 websites
.cz25 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-28176

Top websites that are affected by CVE-2026-28176. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.golf France***,***
********.com United States***,***
*********.fr France***,***
************.fr France***,***
*************.ch Switzerland***,***
***********.***.au Australia***,***
****************.de Germany***,***
************.fr France*,***,***
******.eu France*,***,***
****.cz Czech Republic*,***,***
See full domain list

FAQ

CVE-2026-28176 is Deserialization of Untrusted Data in Booking Activities
A total of 1,276 websites have been identified as vulnerable to CVE-2026-28176, based on global website indexing conducted by WebTechSurvey.
The Booking Activities is affected by the CVE-2026-28176 vulnerability.
Booking Activities versions up to and including 1.18.4 are vulnerable to CVE-2026-28176.