Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-86837— Bookly < 28.3 - Unauthenticated Customer PII Update via Verification Bypass

Quick assessment

Affected
Unknown Bookly
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Bookly WordPress 插件在 28.3 版本之前未能在更新客户存储的信息之前正确验证客户身份,使得知道客户主标识符的未认证攻击者能够覆盖该客户的个人存储信息,如姓名、电子邮件和地址。

CVSS 5.3 · Medium EPSS 0.18% · P7
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-86837

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Bookly < 28.3 - Unauthenticated Customer PII Update via Verification Bypass
Source: CVE Program / CVE List V5
Vulnerability Description
The Bookly WordPress plugin before 28.3 does not properly verify a customer's identity before updating their stored details, allowing unauthenticated attackers who know a customer's primary identifier to overwrite that customer's stored personal information such as name, email and address.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown Bookly 0 ~ 28.3 -

II. Public POCs for CVE-2026-86837

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-86837

请登录查看更多情报信息。

Other References for CVE-2026-86837 (1)

Same Patch Batch · Unknown · 2026-09-25 · 6 CVEs total

CVE-2026-80514 5.3 MEDIUM wpForo Forum 3.0.0 - 3.1.5 - Unauthenticated AI Credit Exhaustion via IP Rate Limit Bypass
CVE-2026-88848 4.2 MEDIUM MasterStudy LMS 1.9 - < 3.7.50 - Subscriber+ Membership Plan Quota and Category Restrictio
CVE-2026-78394 Link Library < 7.9.6 - Contributor+ Path Traversal via 'filepath' Parameter
CVE-2026-78397 Link Library < 7.9.6 - Unauthenticated SSRF via Reciprocal Link Validation
CVE-2026-78393 Link Library < 7.9.6 - Reflected XSS via 'link_tags' and 'link_price' Sort and Breadcrumb

IV. Related Vulnerabilities

V. Comments for CVE-2026-86837

No comments yet


Leave a comment