5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Description
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation via the 'tips' parameter in all versions up to, and including, 27.0. This is due to the plugin trusting a user-supplied input without server-side validation against the configured price. This makes it possible for unauthenticated attackers to submit a negative number to the 'tips' parameter, causing the total price to be reduced to zero.
Basic Information
ID
CVE-2026-2519
Source
Wordfence
Published
Apr 9, 2026 at 12:28
Affected Product
Vendor
ladela
Product
Online Scheduling and Appointment Booking System – Bookly
Affected Versions
ladela Online Scheduling and Appointment Booking System – Bookly 0
CWE Classification
References
- www.wordfence.com /threat-intel/vulnerabilities/id/ead87d8b-2659-4e8b-a0b9-138b1db89e36
- plugins.trac.wordpress.org /browser/bookly-responsive-appointment-booking-tool/trunk/lib/UserBookingData.php
- plugins.trac.wordpress.org /browser/bookly-responsive-appointment-booking-tool/trunk/frontend/modules/booking/Ajax.php
- plugins.trac.wordpress.org /browser/bookly-responsive-appointment-booking-tool/trunk/lib/CartInfo.php
- plugins.trac.wordpress.org /changeset/3480956/
- www.booking-wp-plugin.com /change-log/