Insecure Direct Object Reference in Online Scheduling Plugin for WordPress
CVE-2026-89063

7.5HIGH

What is CVE-2026-89063?

The Bookly plugin for WordPress has a vulnerability that allows unauthorized users to exploit the 'conversation_id' parameter. This oversight enables attackers to access AI booking conversation transcripts, revealing sensitive information such as names, emails, phone numbers, and appointment details. Furthermore, attackers can inject arbitrary messages into conversations, which could be relayed to the Cloud AI worker, compromising user privacy. The flaw arises from insufficient validation for user-controlled keys, allowing unauthorized enumeration of customer conversations by incrementing the 'conversation_id'.

Affected Version(s)

Online Scheduling and Appointment Booking System – Bookly 0 <= 28.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

jtb75
.