Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-86838 1 Wordpress-extensions 1 Bookly 2026-09-28 5.3 Medium
The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book paid services for free while bypassing the payment step.
CVE-2026-86841 1 Wordpress-extensions 1 Bookly 2026-09-28 4.7 Medium
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged maintenance feature to administrators, allowing users granted a custom booking-management capability, which an administrator must explicitly assign, to inject arbitrary PHP objects, overwrite privileged site options, and read stored integration secrets.
CVE-2026-86839 1 Wordpress-extensions 1 Bookly 2026-09-28 3.8 Low
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff members' appointments and payments, including the associated customer's personal information.