Impact
The Bookly appointment booking plugin for WordPress can deserialize untrusted input via the value parameter, allowing an authenticated attacker with custom-level or higher access to inject a PHP object. This weakness is identified as CWE-502, PHP Object Injection, which exposes the system to potential arbitrary code execution. While no gadget chain is publicly documented, the vulnerability represents a potential vector for arbitrary code execution within the WordPress environment, depending on future exploitation developments.
Affected Systems
The vulnerability affects all Bookly versions up to and including 28.2. Operators using these plugin releases should verify whether their installation incorporates one of these versions and consider upgrading to a non‑vulnerable release.
Risk and Exploitability
The CVSS base score of 7.2 denotes a high severity risk. EPSS data is presently unavailable, and the vulnerability is not listed in the CISA KEV catalog. The attack requires authentication; an adversary must possess a custom‑level or higher account. Because no gadget chain has been identified, the exploitability is uncertain, but the potential for code execution remains significant if an appropriate object dominates are introduced.
OpenCVE Enrichment