CVE-2026-2519 | ladela Bookly Plugin up to 27.0 on WordPress Negative Number tips external control of assumed-immutable web parameter (EUVD-2026-20890)
A vulnerability, which was classified as critical, was found in ladela Bookly Plugin up to 27.0 on WordPress. Affected by this vulnerability is an unknown functionality of the component Negative Number Handler. Executing a manipulation of the argument tips can lead to external control of assumed-immutable web parameter.
The identification of this vulnerability is CVE-2026-2519. The attack may be launched remotely. There is no exploit available.