CVE-2026-86841
Received Received - Intake

Unauthenticated PHP Object Injection in Online Scheduling Plugin

Vulnerability report for CVE-2026-86841, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: WPScan

Description

The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged maintenance feature to administrators, allowing users granted a custom booking-management capability, which an administrator must explicitly assign, to inject arbitrary PHP objects, overwrite privileged site options, and read stored integration secrets.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-27
AI Q&A
2026-09-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
bookly plugin to 28.3 (exc)
bookly plugin 28.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a PHP Object Injection flaw in the Bookly WordPress plugin versions 23.2 to 28.2. It occurs because the plugin does not properly restrict deserialization of untrusted input and fails to limit a privileged maintenance feature to administrators only. Users with a custom booking-management capability can exploit this to inject arbitrary PHP objects, overwrite site options, and access stored integration secrets.

Detection Guidance

Check the installed version of the Bookly plugin. If it is between 23.2 and 28.2, the system is vulnerable. Look for unauthorized changes in site options or access to integration secrets.

Impact Analysis

An attacker with the custom booking-management capability could exploit this to take control of your WordPress site, modify settings, or steal sensitive data like integration secrets. This could lead to further attacks or data breaches.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR and HIPAA requirements for data protection and access control. Organizations using the affected plugin may face compliance violations and potential legal consequences.

Mitigation Strategies

Update the Bookly plugin to version 28.3 or later immediately. Remove any custom booking-management capabilities assigned to non-administrative users to limit exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86841. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart