Insecure Direct Object Reference in Bookly Plugin for WordPress
CVE-2026-93399

9.1CRITICAL

What is CVE-2026-93399?

The Bookly plugin for WordPress is susceptible to an Insecure Direct Object Reference vulnerability affecting versions up to and including 28.2. This flaw arises from the 'bookly_get_form_id' AJAX handler, which improperly processes the 'order_id' supplied by users, allowing an attacker to exploit this by creating new booking sessions. As a result, unauthenticated users can sequentially enumerate order IDs, retrieve confidential order tokens, and access appointment data through the 'bookly_add_to_calendar' action. Additionally, this vulnerability enables unauthorized users to delete incomplete bookings via the 'bookly_rollback_order' action, leading to cascading deletions of associated customer appointments when those appointments are unlinked from other users.

Affected Version(s)

Online Scheduling and Appointment Booking System – Bookly 0 <= 28.2

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Theklis
.