Insecure Direct Object Reference in Bookly Plugin for WordPress
CVE-2026-93399
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 September 2026
What is CVE-2026-93399?
The Bookly plugin for WordPress is susceptible to an Insecure Direct Object Reference vulnerability affecting versions up to and including 28.2. This flaw arises from the 'bookly_get_form_id' AJAX handler, which improperly processes the 'order_id' supplied by users, allowing an attacker to exploit this by creating new booking sessions. As a result, unauthenticated users can sequentially enumerate order IDs, retrieve confidential order tokens, and access appointment data through the 'bookly_add_to_calendar' action. Additionally, this vulnerability enables unauthorized users to delete incomplete bookings via the 'bookly_rollback_order' action, leading to cascading deletions of associated customer appointments when those appointments are unlinked from other users.
Affected Version(s)
Online Scheduling and Appointment Booking System β Bookly 0 <= 28.2