# Bookly <= 28.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Staff Profile Update

- **ID:** WPSEC-2026-0543
- **Plugin:** Online Scheduling and Appointment Booking System – Bookly (`bookly-responsive-appointment-booking-tool`), https://wordpress.org/plugins/bookly-responsive-appointment-booking-tool/
- **Affected versions:** from 17.4 before 28.5
- **Fixed in:** 28.5 (Update to 28.5 or later.)
- **Severity:** Medium 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N)
- **Weakness:** CWE-639
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/bookly-responsive-appointment-booking-tool
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0543/

## Description

The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 17.4 up to, and including, 28.4. The staff profile save handler loads the staff record linked to the current user, but then applies the request parameters to it, including the record 'id', before saving it. In addition, the removal of 'wp_user_id' acted only on $_POST while the handler reads its parameters from the whole request. This makes it possible for authenticated attackers with subscriber-level access and above who are linked to a staff member to overwrite other staff members' records, for example their name, email address or linked WordPress user, which can move another staff member's appointments into the attacker's own calendar. It also lets them create additional staff records and link a staff record to an arbitrary WordPress user. Exploitation requires the 'Allow staff members to edit their profiles' option, which is enabled by default, or the Staff Cabinet add-on. Modifying another staff member's record requires the site to have more than one staff member.

## References

- https://wpsec.com/vuln/WPSEC-2026-0543/
- https://plugins.svn.wordpress.org/bookly-responsive-appointment-booking-tool/tags/28.5/
- https://wordpress.org/plugins/bookly-responsive-appointment-booking-tool/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0543/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
