Bookly <= 28.4 - Unauthenticated Sensitive Information Exposure via Booking Form Info Text
- ID
- WPSEC-2026-0544
- Plugin
- Online Scheduling and Appointment Booking System – Bookly (bookly-responsive-appointment-booking-tool)
- Affected
- from 20.6 before 28.5
- Remediation
- Update to 28.5 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-200
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
- Attack surface
- Bookly on WPSec AttackSurface
- Fix released
- Published
Description
The Bookly plugin for WordPress is vulnerable to Sensitive Information Exposure via the booking form info texts in versions 20.6 up to, and including, 28.4. When filling in the client placeholders, the plugin uses the stored record of an existing customer matched by the email address or phone number entered in the form, without confirming that the visitor owns that record. This makes it possible for unauthenticated attackers who know an existing customer's email address or phone number to view that customer's other stored details, such as name, phone number, address and notes, on later steps of the booking form. Exploitation requires a booking form info text to be customized to include client placeholders such as {client_address} or {client_phone}. Unless customer details verification is disabled, the attacker must also enter details that do not conflict with the stored record, such as the customer's name.
References
- https://wpsec.com/vuln/WPSEC-2026-0544/
- https://plugins.svn.wordpress.org/bookly-responsive-appointment-booking-tool/tags/28.5/
- https://wordpress.org/plugins/bookly-responsive-appointment-booking-tool/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS