PatchSiren cyber security CVE debrief
CVE-2026-12626 ladela CVE debrief
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 28.2 via deserialization of untrusted input via the ‘value’ parameter. Authenticated attackers with custom-level access and above can inject a PHP Object. No known gadget chain is available. This vulnerability allows attackers to potentially execute arbitrary code, which can lead to significant impact on the confidentiality, integrity, and availability of affected systems.
- Vendor
- ladela
- Product
- Online Scheduling and Appointment Booking System – Bookly
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for WordPress systems with the Online Scheduling and Appointment Booking System – Bookly plugin installed should assess exposure and prioritize verification and potential remediation.
Why it matters
Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems, especially those with custom-level access and above, due to the risk of PHP Object Injection.
- Verification of exposure and potential exploitation attempts
- Assessment of the impact on systems with custom-level access and above
- Prioritization of remediation based on the CVSS score and affected versions
Technical summary
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 28.2 via deserialization of untrusted input via the ‘value’ parameter. This makes it possible for authenticated attackers, with custom-level access and above, to inject a PHP Object. The vulnerability is caused by the deserialization of untrusted input, which can allow attackers to execute arbitrary code. No known gadget chain is available, but the vulnerability still poses a significant risk to affected systems.
Defensive priority
Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems, especially those with custom-level access and above.
Recommended defensive actions
- Verify the version of the Online Scheduling and Appointment Booking System – Bookly plugin and upgrade to a patched version if necessary
- Restrict access to the ‘value’ parameter to prevent authenticated attackers from injecting PHP Objects
- Monitor systems for potential exploitation attempts
- Implement additional security measures such as web application firewalls and intrusion detection systems
- Conduct regular security audits and vulnerability assessments
- Review and update incident response plans to address potential exploitation
- Track and analyze logs for suspicious activity
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description, CVSS score, and affected versions. The vulnerability is caused by the deserialization of untrusted input via the ‘value’ parameter, which can allow attackers to inject PHP objects. The CVE record notes that no known gadget chain is available, but the vulnerability still poses a significant risk to affected systems. Evidence is limited to the CVE record and source item, and defenders should verify the vulnerability and assess its impact on
Sources and references
Verified primary and authoritative sources
-
CVE-2026-12626 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-12626
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-12626 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12626
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Online Scheduling and Appointment Booking System <= 28.2 - Authenticated (Custom+) PHP Object In
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/12xxx/CVE-2026-12626.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/changeset/3707284/bookly-responsive-appointment-booking-tool
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.