Junglewise Threat Intelligence

CVE-2026-57621: Arraytics Booktics PHP object injection

CVE-2026-57621 · Severity: critical · CVSS 9.8 · Published 2026-07-02

Technologies: Arraytics Booktics. Vendors: Arraytics.

Executive brief

Booktics, a WordPress plugin used for booking and scheduling, contains a critical security flaw that allows unauthorized individuals to execute malicious code on the website. By sending specially crafted data to the site, an attacker could potentially take full control of the server, access sensitive customer information, or disrupt business operations. This vulnerability is highly dangerous because it requires no login credentials to exploit.

Technical details

The Booktics plugin for WordPress is vulnerable to PHP Object Injection in versions up to and including 1.0.21 due to the unsafe deserialization of user-supplied input (CWE-502). An unauthenticated remote attacker can exploit this by submitting a specially crafted payload to a vulnerable endpoint. If a suitable Property-Oriented Programming (POP) chain is present in the environment, this can lead to remote code execution, SQL injection, or arbitrary file deletion. The issue is resolved in version 1.0.22.

Affected products

  • Arraytics Booktics <= 1.0.21

Timeline

  • 2026-06-01: disclosed: Reported by hhhai to Patchstack
  • 2026-06-29: advisory: Patchstack advisory published
  • 2026-07-02: patched: NVD publication and patch availability confirmed for version 1.0.22

References

Related threats