CVE-2026-2520 | ladela Bookly Plugin up to 27.2 on WordPress Capability Check main.php updateAddon improper authorization
A vulnerability identified as problematic has been detected in ladela Bookly Plugin up to 27.2 on WordPress. The affected element is the function updateAddon of the file main.php of the component Capability Check. The manipulation leads to improper authorization.
This vulnerability is traded as CVE-2026-2520. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More