CVE-2026-2520 Overview
CVE-2026-2520 affects the Bookly plugin for WordPress, a popular online scheduling and appointment booking system. The vulnerability stems from a missing capability check on the updateAddon function in all versions up to and including 27.2. Authenticated attackers with Subscriber-level access or higher can update any plugin whose main file is named main.php to its latest version. The weakness is classified as Missing Authorization [CWE-862] and carries a network attack vector with low privileges required.
Critical Impact
Subscriber-level users can trigger unauthorized plugin updates on affected WordPress installations, potentially disrupting site functionality or forcing installation of updated code without administrator consent.
Affected Products
- Bookly – Online Scheduling and Appointment Booking System plugin for WordPress
- All versions up to and including 27.2
- WordPress sites permitting Subscriber-level registration
Discovery Timeline
- 2026-09-08 - CVE-2026-2520 published to the National Vulnerability Database (NVD)
- 2026-09-08 - Last updated in NVD database
Technical Details for CVE-2026-2520
Vulnerability Analysis
The Bookly plugin exposes an updateAddon action handler intended for administrative use. The handler triggers WordPress plugin update routines against any installed plugin whose main file matches main.php. Because the function omits a capability check, WordPress treats any authenticated session as authorized to invoke it. This creates a broken access control condition that low-privileged users can abuse to modify site state.
Root Cause
The root cause is a missing current_user_can() capability verification within the updateAddon handler in lib/PluginsUpdater.php. WordPress relies on plugin developers to enforce capability checks on privileged AJAX and admin-post endpoints. Bookly registers the handler without gating access to users holding update_plugins or equivalent capabilities, allowing any authenticated role to reach the update logic.
Attack Vector
An attacker authenticates to a target WordPress site using a Subscriber account, which many sites allow through open registration. The attacker then issues a request to the vulnerable Bookly endpoint identifying a target plugin. If that plugin's entry file is named main.php, the server triggers an update to the latest available version. The impact includes integrity and availability degradation, since forced updates may break dependent functionality, introduce incompatibilities, or overwrite pinned versions maintained for stability.
The vulnerability mechanism is documented in the referenced WordPress Plugin Code Snippet at line 10 and line 105, with the corrective fix committed in WordPress Changeset #3504922.
Detection Methods for CVE-2026-2520
Indicators of Compromise
- Unexpected plugin version changes recorded in WordPress wp_options or update logs without corresponding administrator activity.
- HTTP POST requests to Bookly AJAX endpoints referencing updateAddon originating from Subscriber-level user sessions.
- New Subscriber account registrations shortly followed by requests targeting the Bookly plugin update handler.
Detection Strategies
- Review web server access logs for requests to admin-ajax.php or admin-post handlers invoking the updateAddon action from non-administrator accounts.
- Correlate WordPress user role data with plugin update events to identify updates initiated by low-privileged sessions.
- Deploy a WordPress security plugin or Web Application Firewall (WAF) rule to flag capability-check bypass patterns against Bookly endpoints.
Monitoring Recommendations
- Enable audit logging for all plugin install, update, and activate events across WordPress installations running Bookly.
- Alert on plugin version changes that occur outside scheduled maintenance windows or without corresponding administrator authentication.
- Monitor for spikes in Subscriber account creation followed by requests to plugin management endpoints.
How to Mitigate CVE-2026-2520
Immediate Actions Required
- Update the Bookly plugin to a version released after 27.2 that incorporates the fix from WordPress Changeset #3504922.
- Audit existing user accounts and remove or downgrade unnecessary Subscriber-level accounts.
- Review recent plugin update history for unexplained version changes and roll back where operationally required.
Patch Information
The vendor addressed the missing capability check in the Bookly plugin repository. The fix is committed in WordPress Changeset #3504922 and detailed in the Wordfence Vulnerability Report. Administrators should upgrade to the patched release through the WordPress plugin management console.
Workarounds
- Disable open user registration or restrict the default new-user role to prevent untrusted accounts from reaching authenticated endpoints.
- Deploy WAF rules that block requests to Bookly AJAX actions originating from non-administrator sessions until patching is complete.
- Temporarily deactivate the Bookly plugin on high-value sites if immediate patching is not feasible.
# Configuration example: restrict default WordPress registration role
# Add to wp-config.php or via WordPress Settings > General
update_option('users_can_register', 0);
update_option('default_role', 'subscriber');
# Verify installed Bookly version via WP-CLI
wp plugin get bookly-responsive-appointment-booking-tool --field=version
# Update Bookly to the patched release
wp plugin update bookly-responsive-appointment-booking-tool
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
