WordPress Plugin Vulnerabilities

Bookly < 27.1 - Unauthenticated Price Manipulation via 'tips'

Description

The plugin is vulnerable to price manipulation via the 'tips' parameter due to the plugin trusting a user-supplied input without server-side validation against the configured price. This makes it possible for unauthenticated attackers to submit a negative number to the 'tips' parameter, causing the total price to be reduced to zero.

Affects Plugins

References

Miscellaneous

Original Researcher
Youssef Elouaer
Verified
No

Timeline

Publicly Published
2026-04-08 (about 1 month ago)
Added
2026-04-09 (about 1 month ago)
Last Updated
2026-04-09 (about 1 month ago)

Other