<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-12626 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-12626/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 07:52:31 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-12626/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>PHP Object Injection Vulnerability in Bookly WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-bookly-php-injection/</link><pubDate>Sat, 10 Oct 2026 07:52:31 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-bookly-php-injection/</guid><description>The Bookly plugin for WordPress contains a PHP Object Injection vulnerability in versions 28.2 and earlier, allowing authenticated users with custom-level access to inject arbitrary PHP objects.</description><content:encoded><![CDATA[<p>The Bookly plugin for WordPress is affected by a PHP Object Injection vulnerability tracked as CVE-2026-12626. The issue stems from insecure deserialization of untrusted input provided through the 'value' parameter within the plugin. An attacker must possess at least custom-level access to the WordPress application to exploit this flaw. By injecting a malicious serialized PHP object, an attacker could potentially achieve remote code execution (RCE) if specific gadget chains are present within the target environment's codebase. As of this report, there is no known functional gadget chain, but the ability to inject arbitrary objects represents a significant security risk for WordPress installations utilizing this plugin for appointment scheduling. Organizations should prioritize updating the plugin to the latest version.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows authenticated attackers with elevated privileges to execute arbitrary code within the context of the web server. This could lead to full site compromise, data exfiltration of appointment and customer records, or lateral movement into the hosting infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the Bookly WordPress plugin to the version released following 28.2 to mitigate CVE-2026-12626.</li>
<li>Review WordPress user roles and capabilities to ensure that custom-level access or higher is restricted to trusted, verified administrators.</li>
<li>Audit server-side application logs for suspicious HTTP POST requests containing serialized PHP data structures targeted at the Bookly plugin endpoints.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>php-injection</category><category>wordpress</category><category>cve-2026-12626</category></item></channel></rss>