WordPress Plugin Vulnerabilities
Bookly < 27.1 - Unauthenticated Price Manipulation via 'tips'
Description
The plugin is vulnerable to price manipulation via the 'tips' parameter due to the plugin trusting a user-supplied input without server-side validation against the configured price. This makes it possible for unauthenticated attackers to submit a negative number to the 'tips' parameter, causing the total price to be reduced to zero.
Affects Plugins
References
Miscellaneous
Original Researcher
Youssef Elouaer
Verified
No
WPVDB ID
Timeline
Publicly Published
2026-04-08 (about 1 month ago)
Added
2026-04-09 (about 1 month ago)
Last Updated
2026-04-09 (about 1 month ago)