SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-78257

HIGH · CVSS 8.8 EPSS 0.48%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Booking and Rental Manager plugin versions up to 2.7.5 are vulnerable to PHP Object Injection, which could allow an attacker to execute arbitrary code or manipulate application behavior. This high-severity vulnerability poses significant risks to the integrity and security of affected systems. Organizations using this plugin should prioritize immediate updates or mitigations to safeguard against potential exploitation.

CVE
CVE-2026-78257
Severity
HIGH
CVSS
8.8
EPSS
0.48%

Original NVD Description

Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.