CVE-2026-12626
Online Scheduling and Appointment Booking System <= 28.2 - Authenticated (Custom+) PHP Object Injection via 'value' Parameter
CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 28.2 via deserialization of untrusted input via the ‘value’ parameter. This makes it possible for authenticated attackers, with custom-level access and above, to inject a PHP Object. No known gadget chain is available.
| CWE | CWE-502 |
| Vendor | ladela |
| Product | online scheduling and appointment booking system – bookly |
| Published | Oct 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for ladela online scheduling and appointment booking system – bookly
Be the first to know when new high vulnerabilities affecting ladela online scheduling and appointment booking system – bookly are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
ladela / Online Scheduling and Appointment Booking System – Bookly
0 ≤ 28.2
References
Credits
Muni Nitish Kumar Yaddala (Stranger825)