Vulnerabilities / Bookly / WPSEC-2026-0543

Bookly <= 28.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Staff Profile Update

Medium 5.4 CWE-639Fixed in 28.5
ID
WPSEC-2026-0543
Plugin
Online Scheduling and Appointment Booking System – Bookly (bookly-responsive-appointment-booking-tool)
Affected
from 17.4 before 28.5
Remediation
Update to 28.5 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Weakness
CWE-639
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
Attack surface
Bookly on WPSec AttackSurface
Fix released
Published

Description

The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 17.4 up to, and including, 28.4. The staff profile save handler loads the staff record linked to the current user, but then applies the request parameters to it, including the record 'id', before saving it. In addition, the removal of 'wp_user_id' acted only on $_POST while the handler reads its parameters from the whole request. This makes it possible for authenticated attackers with subscriber-level access and above who are linked to a staff member to overwrite other staff members' records, for example their name, email address or linked WordPress user, which can move another staff member's appointments into the attacker's own calendar. It also lets them create additional staff records and link a staff record to an arbitrary WordPress user. Exploitation requires the 'Allow staff members to edit their profiles' option, which is enabled by default, or the Staff Cabinet add-on. Modifying another staff member's record requires the site to have more than one staff member.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0