CVE-2026-86838 | Bookly Plugin up to 28.2 on WordPress external control of assumed-immutable web parameter

SecurityVulns

A vulnerability described as problematic has been identified in Bookly Plugin up to 28.2 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation results in external control of assumed-immutable web parameter.

This vulnerability is reported as CVE-2026-86838. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More