CVE-2026-92799

CVE-2026-92799 published: The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in all versions up to, and including, 28.2. This is due to the `postValidateCustomer()` function using a loose PHP...

View full NVD advisory → ← Back to CVE watch