Junglewise Threat Intelligence

CVE-2026-86838: Bookly WordPress plugin payment bypass via booking price manipulation

CVE-2026-86838 · Severity: medium · CVSS 5.3 · Published 2026-09-28

Technologies: Bookly. Vendors: Bookly.

Executive brief

Bookly is a WordPress plugin for managing appointment bookings and payments. The plugin fails to validate booking quantity values on the server, allowing attackers to manipulate prices and book paid services for free by bypassing payment requirements entirely.

Technical details

The vulnerability is a business logic flaw where client-supplied booking quantity values are not validated server-side before computing appointment totals. An unauthenticated attacker can manipulate the quantity parameter to reduce the total price to zero, bypassing the payment processing step and completing bookings at no cost.

Affected products

  • Bookly Bookly before 28.3

Timeline

  • 2026-09-25: disclosed
  • 2026-09-28: patched: Version 28.3 released

References

Related threats