CVE-2026-14516 | ladela Bookly Plugin up to 27.5 on WordPress SQL Query Construction bookly_get_form_id/bookly_render_time staff_ids sql injection

SecurityVulns

A vulnerability categorized as critical has been discovered in ladela Bookly Plugin up to 27.5 on WordPress. The affected element is the function bookly_get_form_id/bookly_render_time of the component SQL Query Construction. Executing a manipulation of the argument staff_ids can lead to sql injection.

This vulnerability appears as CVE-2026-14516. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More