Sceawere
Vulnerability Detail
CVE-2026-86838UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Bookly Payment Bypass Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 2h ago
- Vendor
- Unknown
- Product
- Bookly
- Attack Type
- CWE-472 External Control of Assumed-Immutable Web Parameter
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book paid services for free while bypassing the payment step.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-09-28T07:17:20.953Z",
"pubdate": "2026-09-28T07:17:20.953Z",
"executiveSummary": "The Bookly WordPress plugin, specifically versions prior to 28.3, contains a critical security vulnerability related to improper input validation during the appointment booking process.\nThe vulnerability is characterized by a failure to perform server-side validation of client-supplied booking quantities, which directly impacts the calculation of the total appointment cost.\nThis flaw allows unauthenticated attackers to manipulate the quantity parameters of a booking request to reduce the computed total to zero.\nBy successfully manipulating this total, an attacker can bypass the integrated payment gateway and complete the checkout process for paid services at no cost.\nThe risk implication is significant as it facilitates unauthorized service procurement, leading to direct financial loss for site administrators and potential abuse of booking infrastructure.\nNo authentication is required to perform this exploit, as the vulnerable code path is exposed to public-facing booking forms, making it highly accessible to external actors.\nSuccessful exploitation requires only the ability to intercept and modify standard HTTP requests sent during the booking workflow.",
"technicalDetails": "The root cause of this vulnerability lies in an insecure implementation of the booking logic within the Bookly plugin where client-side input regarding the quantity of service units is implicitly trusted by the backend.\nThe application calculates the total cost of an appointment based on a formula that includes a quantity parameter supplied via the booking request payload. Because the plugin fails to re-validate this quantity against the actual service pricing or availability logic on the server, an attacker can supply arbitrary, non-positive, or modified values.\nIn the attack flow, an unauthenticated user initiates a booking session through the standard front-end interface. Using an intercepting proxy or browser developer tools, the attacker monitors the outbound AJAX requests or POST data sent to the server when moving to the final booking step.\nBy modifying the booking quantity parameter—typically set to '1' by default—to a value that forces the mathematical computation of the total cost to resolve to zero or a negative value, the attacker triggers the backend logic to finalize the transaction as if payment is not required.\nSince the server lacks an authoritative check to reconcile the 'total' amount received against the actual price defined in the database, the plugin logic incorrectly validates the transaction state, allowing the booking to be persisted in the system.\nThe affected component is the internal calculation logic responsible for processing appointment totals prior to payment gateway invocation. Because the system assumes the quantity is immutable or inherently safe, it bypasses the conditional check that would otherwise enforce payment redirection if the total is greater than zero.\nThis vulnerability is present in all versions prior to 28.3. The lack of server-side state enforcement allows the system to treat the manipulated 'zero-total' request as a legitimate completed transaction, bypassing the redirect to Stripe, PayPal, or other integrated payment processors.\nThe impact is a complete bypass of commercial revenue collection mechanisms. Post-exploitation, the attacker gains a confirmed appointment status within the WordPress database, enabling them to receive service without remuneration, potentially causing service availability disruption or inventory depletion."
}