Junglewise Threat Intelligence

CVE-2026-13395: Bookly Online Scheduling and Appointment Booking System SQL injection in staff_id

CVE-2026-13395 · Severity: info · CVSS 8.6 · Published 2026-07-30

Technologies: Bookly. Vendors: Bookly.

Executive brief

A vulnerability exists in the Bookly appointment booking plugin for WordPress, which is used to manage customer schedules and service bookings. An unauthorized attacker can exploit this flaw to gain access to the website's underlying database. This could lead to the theft of sensitive information, including customer data and encrypted administrator passwords, potentially compromising the entire website.

Technical details

The Bookly plugin for WordPress (versions prior to 27.8) contains a SQL injection vulnerability due to insufficient sanitization and improper casting of the 'staff_id' parameter within unauthenticated front-end booking requests. An attacker can exploit this by sending specially crafted network requests to the booking endpoint, allowing for the execution of arbitrary SQL commands. This can be leveraged to extract sensitive information from the database, such as user metadata and password hashes. The issue is fixed in version 27.8.

Affected products

  • Bookly Bookly (Online Scheduling and Appointment Booking System) < 27.8

Timeline

  • 2026-07-13: disclosed
  • 2026-07-13: patched: Fixed in version 27.8
  • 2026-07-30: advisory: NVD publication date

References

Related threats