CVE-2026-14516

Online Scheduling and Appointment Booking System <= 27.5 - Unauthenticated SQL Injection

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injection via the 'staff_ids' parameter in all versions up to, and including, 27.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires a two-request chain: an attacker first calls the unauthenticated bookly_get_form_id action to seed a booking session carrying malicious staff_ids values, then triggers bookly_render_time to cause the tainted array to reach the vulnerable query; CSRF/nonce validation is absent on both endpoints, meaning this chain can be initiated cross-site.


We have discovered 9,499 live websites that are affected by CVE-2026-14516.

Run a Free Instant Scan




Affected Software

Product  Bookly
Category Appointment Scheduling
Vulnerable Domains9,499 live websites (79% of Bookly install base)
Vulnerable Versions
  • from 0 through 27.5
Vulnerable Versions Count118 versions ( 98% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Jul 28, 2026
  • Updated - Jul 28, 2026

Credits

  • Nguyen Ngoc Duc (duc193) (finder)

Website Distribution by Country

Number of websites using CVE-2026-14516
United States2,369 websites



Germany1,009 websites
France882 websites
Netherlands570 websites
GB463 websites
Italy445 websites
Spain442 websites
Canada238 websites
Switzerland237 websites
Belgium208 websites

Website Distribution by TLD

Number of websites using CVE-2026-14516
.com3,663 websites
.de621 websites
.nl562 websites
.fr492 websites
.it372 websites
.co.uk326 websites
.org231 websites
.es208 websites
.ch199 websites
.be179 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-14516

Top websites that are affected by CVE-2026-14516. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.com Singapore**,***
***********.com United States**,***
****.*******.net United States**,***
******.com Estonia***,***
********.org Spain***,***
****.ru Russia***,***
*************.io Romania***,***
****************.ro Romania***,***
***********.com Japan***,***
**************.com Italy***,***
See full domain list

FAQ

CVE-2026-14516 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Bookly
A total of 9,499 websites have been identified as vulnerable to CVE-2026-14516, based on global website indexing conducted by WebTechSurvey.
The Bookly is affected by the CVE-2026-14516 vulnerability.
Bookly versions up to and including 27.5 are vulnerable to CVE-2026-14516.