CVE-2026-13395
Bookly < 27.8 - Unauthenticated SQL Injection via staff_id
CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th
The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data such as password hashes from the database.
| Vendor | unknown |
| Product | online scheduling and appointment booking system |
| Published | Jul 30, 2026 |
| Last Updated | Jul 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown online scheduling and appointment booking system
Be the first to know when new high vulnerabilities affecting unknown online scheduling and appointment booking system are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Online Scheduling and Appointment Booking System
0 < 27.8
References
Credits
Jakub Herman WPScan