CVE-2026-2519: Online Scheduling and Appointment Booking System – Bookly <= 27.0 - Unauthenticated Price Manipulation via 'tips'
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation via the 'tips' parameter in all versions up to, and including, 27.0. This is due to the plugin trusting a user-supplied input without server-side validation against the configured price. This makes it possible for unauthenticated attackers to submit a negative number to the 'tips' parameter, causing the total price to be reduced to zero.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2519?
CVE-2026-2519 is considered a high severity vulnerability due to its potential for allowing unauthenticated price manipulation.
How do I fix CVE-2026-2519?
To fix CVE-2026-2519, you should update the Bookly plugin to version 27.1 or later.
What versions of Bookly are affected by CVE-2026-2519?
CVE-2026-2519 affects all versions of the Bookly plugin up to and including 27.0.
What kind of attack can exploit CVE-2026-2519?
CVE-2026-2519 can be exploited to manipulate prices by altering the 'tips' parameter without authentication.
Is authentication required to exploit CVE-2026-2519?
No, CVE-2026-2519 can be exploited without any authentication, making it particularly dangerous.