PHP Object Injection Vulnerability in Bookly WordPress Plugin
The Bookly plugin for WordPress contains a PHP Object Injection vulnerability in versions 28.2 and earlier, allowing authenticated users with custom-level access to inject arbitrary PHP objects.
CVE search metadata
CVE search record: CVE-2026-12626. Severity: high. CVSS: 7.2. KEV: no. Product: Bookly (<= 28.2). Brief: PHP Object Injection Vulnerability in Bookly WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-bookly-php-injection/
The Bookly plugin for WordPress is affected by a PHP Object Injection vulnerability tracked as CVE-2026-12626. The issue stems from insecure deserialization of untrusted input provided through the 'value' parameter within the plugin. An attacker must possess at least custom-level access to the WordPress application to exploit this flaw. By injecting a malicious serialized PHP object, an attacker could potentially achieve remote code execution (RCE) if specific gadget chains are present within the target environment's codebase. As of this report, there is no known functional gadget chain, but the ability to inject arbitrary objects represents a significant security risk for WordPress installations utilizing this plugin for appointment scheduling. Organizations should prioritize updating the plugin to the latest version.
Impact
Successful exploitation allows authenticated attackers with elevated privileges to execute arbitrary code within the context of the web server. This could lead to full site compromise, data exfiltration of appointment and customer records, or lateral movement into the hosting infrastructure.
Recommendation
- Update the Bookly WordPress plugin to the version released following 28.2 to mitigate CVE-2026-12626.
- Review WordPress user roles and capabilities to ensure that custom-level access or higher is restricted to trusted, verified administrators.
- Audit server-side application logs for suspicious HTTP POST requests containing serialized PHP data structures targeted at the Bookly plugin endpoints.
Immediate actions
Upgrade Bookly plugin to the latest version to patch CVE-2026-12626
Enrichment needed
- Identify active exploit chains for CVE-2026-12626 (CTI) Assess risk level based on availability of weaponized payloads
Mitigations
Review and audit user accounts with custom-level access or higher
CVE-2026-12626