CVE-2026-86838
Last modified
CVE-2026-86838 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book paid services for free while bypassing the payment step..
Description
The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book paid services for free while bypassing the payment step.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | Bookly | < 28.3 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-86838?
How severe is CVE-2026-86838?
How do I fix CVE-2026-86838?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-86824The Newsletter WordPress plugin before 9.3.8 does not gener…4.8
- CVE-2026-8683Mattermost Desktop App versions <=6.1 5.5.13.0 fail to accou…6.5
- CVE-2026-86830Incorrect privilege assignment in Temporary Elevated Access …7.2
- CVE-2026-86831Improper validation of pod identifier uniqueness in aws-netw…8.7
- CVE-2026-86836In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent c…8.4
- CVE-2026-86837The Bookly WordPress plugin before 28.3 does not properly ve…5.3
- CVE-2026-86839The Online Scheduling and Appointment Booking System WordPr…3.8
- CVE-2026-8684The MotoPress Hotel Booking plugin for WordPress is vulnerab…5.3
- CVE-2026-86840The `vtoken-minting` and `slpx` pallets in Bifrost contain a…9.1
- CVE-2026-86841The Online Scheduling and Appointment Booking System WordPr…4.7
- CVE-2026-86842The Real3D Flipbook WordPress plugin before 5.4 does not pe…6.8
- CVE-2026-8685The Infility Global plugin for WordPress is vulnerable to SQ…6.5
Are you affected by CVE-2026-86838?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
