A vulnerability was found in Bookly Plugin up to 27.7 on WordPress. It has been declared as critical. Impacted is an unknown function. Such manipulation leads to sql injection.
This vulnerability is referenced as CVE-2026-61949. It is possible to launch the attack remotely. No exploit is available.