CVE-2026-2519Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation via the 'tips' parameter in all versions up to, and including, 27.0. This is due to the plugin trusting a user-supplied input without server-side validation against the configured price. This makes it possible for unauthenticated attackers to submit a negative number to the 'tips' parameter, causing the total price to be reduced to zero.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-472

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-09: 3Technical Details · 2026-04-09: 304-09
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-2519 The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation via the 'tips' parameter in all versions up to, a… https://www.cve.org/CVERecord?id=CVE-2026-2519 ----- Traducción: CVE-2026-2519 El … http://infoflow.cloud`

    Post summary

    CVE-2026-2519 exposes a price manipulation issue in the Bookly WordPress plugin via the 'tips' parameter, as announced in the CVE record, with no reported active exploitation, patches, or PoC code.

    0000058
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2519 The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation via the 'tips' parameter in all versions up to, a… https://www.cve.org/CVERecord?id=CVE-2026-2519

    Post summary

    The CVE-2026-2519 concerns a price‑manipulation flaw in the Bookly WordPress plugin triggered by the 'tips' parameter; no PoC or exploit code is cited, but the issue is documented in a CVE record.

    00000154
    57.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-2519 - Online Scheduling and Appointment Booking System - Bookly <= 27.0 - Unauthenticated Price Manipulation via 'tips' Intel Report: https://ift.tt/Z7nVhNI

    Post summary

    An alert identifies CVE-2026-2519 in Bookly up to version 27.0, describing an unauthenticated price manipulation flaw via the 'tips' feature. No PoC, exploit code, or patch is mentioned.

    0000039
    280 followersView on X

Explore more