CVE WATCH / VULNERABILITY DETAIL

CVE-2026-86838

MEDIUMCVSS 5.3NVD feed

Published 28 September 2026 · tracked since 28 September 2026

Description

The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book paid services for free while bypassing the payment step.

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-86838 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-86838

MEDIUMCVSS 5.3NVD feed

Published 28 September 2026 · tracked since 28 September 2026

Description

The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book paid services for free while bypassing the payment step.

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]