Search
Search Results (3 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-86838 | 1 Wordpress-extensions | 1 Bookly | 2026-09-28 | 5.3 Medium |
| The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book paid services for free while bypassing the payment step. | ||||
| CVE-2026-86841 | 1 Wordpress-extensions | 1 Bookly | 2026-09-28 | 4.7 Medium |
| The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged maintenance feature to administrators, allowing users granted a custom booking-management capability, which an administrator must explicitly assign, to inject arbitrary PHP objects, overwrite privileged site options, and read stored integration secrets. | ||||
| CVE-2026-86839 | 1 Wordpress-extensions | 1 Bookly | 2026-09-28 | 3.8 Low |
| The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff members' appointments and payments, including the associated customer's personal information. | ||||
Page 1 of 1.