CVE-2026-2520
Deferred Deferred - Pending Action

Unauthorized Plugin Update in Bookly WordPress Plugin

Vulnerability report for CVE-2026-2520, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: Wordfence

Description

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'updateAddon' function in all versions up to, and including, 27.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update any plugin with a main file of 'main.php' to its latest version.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-09
AI Q&A
2026-09-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
bookly plugin to 27.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability is in the Bookly plugin for WordPress. It allows authenticated users with Subscriber-level access or higher to modify plugin data due to a missing capability check in the 'updateAddon' function. This could let attackers update any plugin with a main file named 'main.php' to its latest version without proper authorization.

Impact Analysis

An attacker could exploit this to update plugins to malicious versions, potentially gaining control over your WordPress site. This could lead to data breaches, defacement, or further compromise of your website or user data.

Mitigation Strategies

Update the Bookly plugin to the latest version beyond 27.2 immediately to patch the missing capability check in the 'updateAddon' function. Remove any unauthorized plugin updates made by suspicious users.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-2520. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart