Description
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 28.2 via deserialization of untrusted input via the ‘value’ parameter. This makes it possible for authenticated attackers, with custom-level access and above, to inject a PHP Object. No known gadget chain is available.
Published: 2026-10-10
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Code Execution
Action: Apply Patch
AI Analysis

Impact

The Bookly appointment booking plugin for WordPress can deserialize untrusted input via the value parameter, allowing an authenticated attacker with custom-level or higher access to inject a PHP object. This weakness is identified as CWE-502, PHP Object Injection, which exposes the system to potential arbitrary code execution. While no gadget chain is publicly documented, the vulnerability represents a potential vector for arbitrary code execution within the WordPress environment, depending on future exploitation developments.

Affected Systems

The vulnerability affects all Bookly versions up to and including 28.2. Operators using these plugin releases should verify whether their installation incorporates one of these versions and consider upgrading to a non‑vulnerable release.

Risk and Exploitability

The CVSS base score of 7.2 denotes a high severity risk. EPSS data is presently unavailable, and the vulnerability is not listed in the CISA KEV catalog. The attack requires authentication; an adversary must possess a custom‑level or higher account. Because no gadget chain has been identified, the exploitability is uncertain, but the potential for code execution remains significant if an appropriate object dominates are introduced.

Generated by OpenCVE AI on October 10, 2026 at 08:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Bookly to a version newer than 28.2 that resolves the PHP Object Injection flaw
  • Revoke custom‑level or higher user permissions from accounts that do not require them and restrict roles that can interact with booking functionality
  • If an upgrade cannot be performed immediately, remove or deactivate the Bookly plugin until a patched version is available

Generated by OpenCVE AI on October 10, 2026 at 08:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 28.2 via deserialization of untrusted input via the ‘value’ parameter. This makes it possible for authenticated attackers, with custom-level access and above, to inject a PHP Object. No known gadget chain is available.
Title Online Scheduling and Appointment Booking System <= 28.2 - Authenticated (Custom+) PHP Object Injection via 'value' Parameter
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T06:40:10.624Z

Reserved: 2026-06-18T14:40:59.125Z

Link: CVE-2026-12626

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T07:16:41.230

Modified: 2026-10-10T07:16:41.230

Link: CVE-2026-12626

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T09:00:03Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data