Authorization Bypass in Bookly Plugin for WordPress
CVE-2026-92799

5.3MEDIUM

What is CVE-2026-92799?

The Bookly Plugin for WordPress contains a critical flaw allowing unauthorized users to bypass the phone/email verification process. This vulnerability stems from the loose comparison operator used in the postValidateCustomer() function, which allows attackers to manipulate the verification code. As all booking AJAX controller methods register as unauthenticated handlers, unauthenticated attackers can change a customer's name, email, phone, and address. By submitting specific inputs, such as the boolean true, attackers can bypass verification, resulting in the potential redirection of booking notifications to their own contact details. The lack of CSRF protection further exacerbates this risk, making it imperative for users to update to secure versions promptly.

Affected Version(s)

Online Scheduling and Appointment Booking System – Bookly 0 <= 28.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

crow
.