Insecure Direct Object Reference Vulnerability in Bookly Plugin for WordPress
CVE-2026-104898

6.8MEDIUM

What is CVE-2026-104898?

The Bookly plugin for WordPress has a vulnerability that allows authenticated users with subscriber-level access and higher to exploit an Insecure Direct Object Reference, specifically through the 'id, wp_user_id' parameter. This lack of validation on a user-controlled key could enable attackers to overwrite the WordPress account associated with any Bookly staff record, including those held by administrators. As a result, an attacker could effectively hijack a higher-privileged account. To exploit this vulnerability, the attacker must be linked to at least one Bookly staff record, which is generally set up by default when the option 'bookly_gen_allow_staff_edit_profile' is enabled.

Affected Version(s)

Online Scheduling and Appointment Booking System – Bookly 0 <= 28.4

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.