Insecure Direct Object Reference in Online Scheduling Plugin for WordPress
CVE-2026-89063
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-89063?
The Bookly plugin for WordPress has a vulnerability that allows unauthorized users to exploit the 'conversation_id' parameter. This oversight enables attackers to access AI booking conversation transcripts, revealing sensitive information such as names, emails, phone numbers, and appointment details. Furthermore, attackers can inject arbitrary messages into conversations, which could be relayed to the Cloud AI worker, compromising user privacy. The flaw arises from insufficient validation for user-controlled keys, allowing unauthorized enumeration of customer conversations by incrementing the 'conversation_id'.
Affected Version(s)
Online Scheduling and Appointment Booking System β Bookly 0 <= 28.1