Sensitive Information Exposure in Bookly Plugin for WordPress
CVE-2026-103365
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-103365?
The Bookly plugin for WordPress contains a vulnerability that allows unauthenticated attackers to access sensitive information. In specific versions up to 28.4, attackers can exploit the classic booking form's Details step, where the endpoint 'bookly_render_details' is improperly configured for both authenticated and unauthenticated requests. The vulnerability arises because the token validation method, csrfTokenValid(), is overridden to always return true, enabling unauthorized access. This flaw permits attackers who possess a registered customer's phone number or email to retrieve personal data, such as the customer's name, email, phone number, and internal notes, from the response HTML. Consequently, if site owners utilize placeholders like {client_name}, {client_email}, or {client_phone} in their booking forms, attackers can easily leverage this information exposure to gain insights into sensitive client data.
Affected Version(s)
Online Scheduling and Appointment Booking System β Bookly 0 <= 28.4