CVE-2026-61949

WordPress Bookly plugin <= 27.7 - SQL Injection vulnerability

Unauthenticated SQL Injection in Bookly <= 27.7 versions.


We have discovered 12,100 live websites that are affected by CVE-2026-61949.

Run a Free Instant Scan




Affected Software

Product  Bookly
Category Appointment Scheduling
Vulnerable Domains12,100 live websites (100% of Bookly install base)
Vulnerable Versions
  • from 0 through 27.7
Vulnerable Versions Count120 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Jul 23, 2026
  • Updated - Jul 23, 2026

Credits

  • dodoh4t | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-61949
United States3,198 websites



Germany1,352 websites
France1,059 websites
Netherlands755 websites
GB617 websites
Spain558 websites
Italy535 websites
Canada307 websites
Switzerland291 websites
Belgium264 websites

Website Distribution by TLD

Number of websites using CVE-2026-61949
.com4,617 websites
.de871 websites
.nl747 websites
.fr593 websites
.it446 websites
.co.uk433 websites
.org348 websites
.es261 websites
.ch249 websites
.be235 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-61949

Top websites that are affected by CVE-2026-61949. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.com Singapore**,***
****************.***.gov United States**,***
***********.com United States**,***
****.****.edu United States**,***
****.*******.net United States**,***
****************.com GB***,***
******.com Estonia***,***
********.org Spain***,***
**************.pt Portugal***,***
***************.com United States***,***
See full domain list

FAQ

CVE-2026-61949 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Bookly
A total of 12,100 websites have been identified as vulnerable to CVE-2026-61949, based on global website indexing conducted by WebTechSurvey.
The Bookly is affected by the CVE-2026-61949 vulnerability.
Bookly versions up to and including 27.7 are vulnerable to CVE-2026-61949.