Vulnerabilities / Bookly / WPSEC-2026-0544

Bookly <= 28.4 - Unauthenticated Sensitive Information Exposure via Booking Form Info Text

Low 3.7 CWE-200Fixed in 28.5
ID
WPSEC-2026-0544
Plugin
Online Scheduling and Appointment Booking System – Bookly (bookly-responsive-appointment-booking-tool)
Affected
from 20.6 before 28.5
Remediation
Update to 28.5 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-200
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
Attack surface
Bookly on WPSec AttackSurface
Fix released
Published

Description

The Bookly plugin for WordPress is vulnerable to Sensitive Information Exposure via the booking form info texts in versions 20.6 up to, and including, 28.4. When filling in the client placeholders, the plugin uses the stored record of an existing customer matched by the email address or phone number entered in the form, without confirming that the visitor owns that record. This makes it possible for unauthenticated attackers who know an existing customer's email address or phone number to view that customer's other stored details, such as name, phone number, address and notes, on later steps of the booking form. Exploitation requires a booking form info text to be customized to include client placeholders such as {client_address} or {client_phone}. Unless customer details verification is disabled, the attacker must also enter details that do not conflict with the stored record, such as the customer's name.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0