---
id: CVE-2026-86838
title: >-
  The Bookly WordPress plugin before 28.3 does not validate client-supplied
  booking quantity values on the server before computing the appointment total,
  allowing unauthenticated users to reduce the total to zero and book paid
  services for…
summary: >-
  The Bookly WordPress plugin before 28.3 does not validate client-supplied
  booking quantity values on the server before computing the appointment total,
  allowing unauthenticated users to reduce the total to zero and book paid
  services for…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-472
product: Bookly
affected:
  - Bookly < 28.3
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T07:17:20.953'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86838'
references:
  - url: 'https://wpscan.com/vulnerability/1c8a53e7-5556-4dcb-a461-c6df253d0b7a/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T07:04:53.492Z'
---

## Overview

The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book paid services for free while bypassing the payment step.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
