Price Manipulation Flaw in Bookly Appointment Booking System for WordPress
CVE-2026-2519
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 April 2026
What is CVE-2026-2519?
The Bookly plugin for WordPress is susceptible to a price manipulation vulnerability through the 'tips' parameter across all versions up to 27.0. This occurs because the plugin fails to adequately validate user inputs on the server side, allowing unauthenticated attackers to exploit this weakness. By sending a negative value via the 'tips' parameter, it is possible to decrease the total price of bookings to zero, thereby undermining the integrity of the booking system.
Affected Version(s)
Online Scheduling and Appointment Booking System β Bookly 0 <= 27.0