PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-12626 ladela CVE debrief

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 28.2 via deserialization of untrusted input via the ‘value’ parameter. Authenticated attackers with custom-level access and above can inject a PHP Object. No known gadget chain is available. This vulnerability allows attackers to potentially execute arbitrary code, which can lead to significant impact on the confidentiality, integrity, and availability of affected systems.

Vendor
ladela
Product
Online Scheduling and Appointment Booking System – Bookly
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders responsible for WordPress systems with the Online Scheduling and Appointment Booking System – Bookly plugin installed should assess exposure and prioritize verification and potential remediation.

Why it matters

Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems, especially those with custom-level access and above, due to the risk of PHP Object Injection.

  • Verification of exposure and potential exploitation attempts
  • Assessment of the impact on systems with custom-level access and above
  • Prioritization of remediation based on the CVSS score and affected versions

Technical summary

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 28.2 via deserialization of untrusted input via the ‘value’ parameter. This makes it possible for authenticated attackers, with custom-level access and above, to inject a PHP Object. The vulnerability is caused by the deserialization of untrusted input, which can allow attackers to execute arbitrary code. No known gadget chain is available, but the vulnerability still poses a significant risk to affected systems.

Defensive priority

Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems, especially those with custom-level access and above.

Recommended defensive actions

  • Verify the version of the Online Scheduling and Appointment Booking System – Bookly plugin and upgrade to a patched version if necessary
  • Restrict access to the ‘value’ parameter to prevent authenticated attackers from injecting PHP Objects
  • Monitor systems for potential exploitation attempts
  • Implement additional security measures such as web application firewalls and intrusion detection systems
  • Conduct regular security audits and vulnerability assessments
  • Review and update incident response plans to address potential exploitation
  • Track and analyze logs for suspicious activity

Evidence notes

The CVE record and source item provide details on the vulnerability, including its description, CVSS score, and affected versions. The vulnerability is caused by the deserialization of untrusted input via the ‘value’ parameter, which can allow attackers to inject PHP objects. The CVE record notes that no known gadget chain is available, but the vulnerability still poses a significant risk to affected systems. Evidence is limited to the CVE record and source item, and defenders should verify the vulnerability and assess its impact on

Sources and references

Verified primary and authoritative sources

  • CVE-2026-12626 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-12626

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-12626 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12626

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.