Insecure Direct Object Reference Vulnerability in Bookly Plugin for WordPress
CVE-2026-104898
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-104898?
The Bookly plugin for WordPress has a vulnerability that allows authenticated users with subscriber-level access and higher to exploit an Insecure Direct Object Reference, specifically through the 'id, wp_user_id' parameter. This lack of validation on a user-controlled key could enable attackers to overwrite the WordPress account associated with any Bookly staff record, including those held by administrators. As a result, an attacker could effectively hijack a higher-privileged account. To exploit this vulnerability, the attacker must be linked to at least one Bookly staff record, which is generally set up by default when the option 'bookly_gen_allow_staff_edit_profile' is enabled.
Affected Version(s)
Online Scheduling and Appointment Booking System β Bookly 0 <= 28.4