Price Manipulation Flaw in Bookly Appointment Booking System for WordPress
CVE-2026-2519

5.3MEDIUM

What is CVE-2026-2519?

The Bookly plugin for WordPress is susceptible to a price manipulation vulnerability through the 'tips' parameter across all versions up to 27.0. This occurs because the plugin fails to adequately validate user inputs on the server side, allowing unauthenticated attackers to exploit this weakness. By sending a negative value via the 'tips' parameter, it is possible to decrease the total price of bookings to zero, thereby undermining the integrity of the booking system.

Affected Version(s)

Online Scheduling and Appointment Booking System – Bookly 0 <= 27.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Youssef Elouaer
.