Authorization Bypass in Bookly Plugin for WordPress
CVE-2026-92799
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 September 2026
What is CVE-2026-92799?
The Bookly Plugin for WordPress contains a critical flaw allowing unauthorized users to bypass the phone/email verification process. This vulnerability stems from the loose comparison operator used in the postValidateCustomer() function, which allows attackers to manipulate the verification code. As all booking AJAX controller methods register as unauthenticated handlers, unauthenticated attackers can change a customer's name, email, phone, and address. By submitting specific inputs, such as the boolean true, attackers can bypass verification, resulting in the potential redirection of booking notifications to their own contact details. The lack of CSRF protection further exacerbates this risk, making it imperative for users to update to secure versions promptly.
Affected Version(s)
Online Scheduling and Appointment Booking System β Bookly 0 <= 28.2