CPE
The Bookly plugin for WordPress contains a PHP Object Injection vulnerability in versions 28.2 and earlier, allowing authenticated users with custom-level access to inject arbitrary PHP objects.