CVE-2026-12626
Received Received - Intake

PHP Object Injection in Bookly WordPress Plugin

Vulnerability report for CVE-2026-12626, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Wordfence

Description

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 28.2 via deserialization of untrusted input via the β€˜value’ parameter. This makes it possible for authenticated attackers, with custom-level access and above, to inject a PHP Object. No known gadget chain is available.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ladela Online Scheduling and Appointment Booking System – Bookly 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a PHP Object Injection flaw in the Bookly WordPress plugin. It allows authenticated attackers with custom-level access or higher to inject a PHP object via the 'value' parameter due to unsafe deserialization of untrusted input. No known exploit chain exists currently.

Detection Guidance

Detection requires checking for the Bookly plugin version up to 28.2. Use WordPress admin to inspect installed plugins or run commands like 'wp plugin list' if using WP-CLI. Look for the Bookly plugin in the list.

Impact Analysis

An attacker could exploit this to execute arbitrary code on your WordPress site, potentially taking control of it. This may lead to data theft, site defacement, or further compromise of your server. The impact is significant as it requires only custom-level access.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR and HIPAA requirements for data protection and confidentiality. Organizations may face fines or penalties for failing to secure sensitive user data.

Mitigation Strategies

Immediately update the Bookly plugin to the latest version beyond 28.2. If updating is not possible, consider disabling the plugin temporarily until a patch is applied. Ensure all WordPress installations are updated to the latest secure versions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12626. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart