Sceawere

Vulnerability Detail

CVE-2026-12626UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Bookly PHP Object Injection Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
3h ago
Vendor
ladela
Product
Online Scheduling and Appointment Booking System – Bookly
Attack Type
CWE-502 Deserialization of Untrusted Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 28.2 via deserialization of untrusted input via the ‘value’ parameter. This makes it possible for authenticated attackers, with custom-level access and above, to inject a PHP Object. No known gadget chain is available.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-10T07:16:41.230Z",
  "pubdate": "2026-10-10T07:16:41.230Z",
  "executiveSummary": "The Bookly plugin for WordPress, in versions up to and including 28.2, contains a critical PHP Object Injection vulnerability. This flaw stems from the improper handling and deserialization of untrusted user-supplied data passed through the 'value' parameter.\nThe vulnerability allows authenticated attackers possessing custom-level access or higher to inject serialized PHP objects into the application. By manipulating the object structure, an attacker may influence the application's internal state or potentially trigger unintended code execution if a suitable gadget chain exists within the environment.\nThis vulnerability poses a significant security risk, as successful exploitation could lead to privilege escalation, unauthorized data access, or arbitrary file manipulation, depending on the available PHP classes within the WordPress environment.\nExploitation requires the attacker to be authenticated with specific privileges, limiting the scope of initial entry but presenting a severe risk to the integrity and availability of the WordPress site.",
  "technicalDetails": "The vulnerability is identified as a PHP Object Injection vulnerability, specifically involving the unsafe deserialization of user input. The application accepts input via the 'value' parameter and passes this data directly to the PHP 'unserialize()' function without adequate validation or sanitization.\nPHP Object Injection occurs when an application deserializes untrusted data that has been manipulated to include malicious object representations. When 'unserialize()' is invoked on this input, PHP reconstructs the object, which can trigger magic methods such as '__wakeup()', '__destruct()', or '__toString()'. These magic methods are executed automatically during the object lifecycle and can be leveraged to conduct various malicious activities if they perform operations on controlled properties.\nThe attack flow proceeds as follows: First, an authenticated attacker with custom-level access or higher identifies the endpoint processing the 'value' parameter. Second, the attacker crafts a malicious serialized PHP payload designed to instantiate or interact with existing classes present within the application's scope. Third, the attacker submits this payload via the vulnerable 'value' parameter. Upon processing, the server-side application deserializes the input, potentially instantiating the injected object and executing associated magic methods.\nAlthough no specific gadget chain is currently publicly identified, the presence of the 'unserialize()' vulnerability allows an attacker to manipulate the object state if any classes are loaded in the application's runtime environment that contain exploitable magic methods. The potential impact of such an injection is highly dependent on the classes available at the time of execution; however, this typically results in unauthorized execution of logic, such as modifying system configurations, deleting files, or escalating privileges by overwriting existing object properties that govern authorization.\nThe vulnerable component is the processing logic handling the 'value' parameter within the Bookly plugin. The affected scope includes all versions up to and including 28.2. Because this flaw resides in a plugin, the vulnerability is exposed to any user with the minimum required privilege level, regardless of external network exposure, as long as the WordPress installation is reachable and the user is authenticated."
}
CVE-2026-12626: Bookly PHP Object Injection Vulnerability (HIGH Severity, CVSS: 7.2) | Sceawere