{
 "id": "WPSEC-2026-0543",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0543/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0543/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0543/index.md",
 "title": "Bookly <= 28.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Staff Profile Update",
 "description": "The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 17.4 up to, and including, 28.4. The staff profile save handler loads the staff record linked to the current user, but then applies the request parameters to it, including the record 'id', before saving it. In addition, the removal of 'wp_user_id' acted only on $_POST while the handler reads its parameters from the whole request. This makes it possible for authenticated attackers with subscriber-level access and above who are linked to a staff member to overwrite other staff members' records, for example their name, email address or linked WordPress user, which can move another staff member's appointments into the attacker's own calendar. It also lets them create additional staff records and link a staff record to an arbitrary WordPress user. Exploitation requires the 'Allow staff members to edit their profiles' option, which is enabled by default, or the Staff Cabinet add-on. Modifying another staff member's record requires the site to have more than one staff member.",
 "plugin": {
  "slug": "bookly-responsive-appointment-booking-tool",
  "name": "Bookly",
  "full_name": "Online Scheduling and Appointment Booking System – Bookly",
  "wordpress_org": "https://wordpress.org/plugins/bookly-responsive-appointment-booking-tool/",
  "advisories_url": "https://wpsec.com/vuln/plugin/bookly-responsive-appointment-booking-tool/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/bookly-responsive-appointment-booking-tool"
 },
 "type": "AUTHBYPASS",
 "cwe": [
  "CWE-639"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.4,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "17.4",
    "from_inclusive": true,
    "to": "28.5",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 17.4 before 28.5"
  ]
 },
 "introduced_in": "17.4",
 "fixed_in": "28.5",
 "remediation": "Update to 28.5 or later.",
 "fix_released": "2026-10-06T13:25:48+00:00",
 "published": "2026-10-07T13:54:10+00:00",
 "updated": "2026-10-06T16:17:06.743240+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0543/",
  "https://plugins.svn.wordpress.org/bookly-responsive-appointment-booking-tool/tags/28.5/",
  "https://wordpress.org/plugins/bookly-responsive-appointment-booking-tool/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/bookly-responsive-appointment-booking-tool",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-07"
 }
}