CVE · High

CVE-2026-42667 — Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 27.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-42667 Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 27.5 Insertion of Sensitive Information Into Sent Data High 7.5 < 27.5 27.5 2026-05-10

CVE-2026-42667

All versions of the Bookly plugin prior to 27.5 contain a security flaw that allows unauthorized access to confidential user information or system settings without requiring authentication. This vulnerability affects every version up to and including 27.4, making it possible for malicious individuals to obtain sensitive details.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.