Executive brief
Bookly is a WordPress plugin for managing appointment bookings and payments. The plugin fails to validate booking quantity values on the server, allowing attackers to manipulate prices and book paid services for free by bypassing payment requirements entirely.
Technical details
The vulnerability is a business logic flaw where client-supplied booking quantity values are not validated server-side before computing appointment totals. An unauthenticated attacker can manipulate the quantity parameter to reduce the total price to zero, bypassing the payment processing step and completing bookings at no cost.
Affected products
- Bookly Bookly before 28.3
Timeline
- 2026-09-25: disclosed
- 2026-09-28: patched: Version 28.3 released