{
 "id": "WPSEC-2026-0544",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0544/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0544/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0544/index.md",
 "title": "Bookly <= 28.4 - Unauthenticated Sensitive Information Exposure via Booking Form Info Text",
 "description": "The Bookly plugin for WordPress is vulnerable to Sensitive Information Exposure via the booking form info texts in versions 20.6 up to, and including, 28.4. When filling in the client placeholders, the plugin uses the stored record of an existing customer matched by the email address or phone number entered in the form, without confirming that the visitor owns that record. This makes it possible for unauthenticated attackers who know an existing customer's email address or phone number to view that customer's other stored details, such as name, phone number, address and notes, on later steps of the booking form. Exploitation requires a booking form info text to be customized to include client placeholders such as {client_address} or {client_phone}. Unless customer details verification is disabled, the attacker must also enter details that do not conflict with the stored record, such as the customer's name.",
 "plugin": {
  "slug": "bookly-responsive-appointment-booking-tool",
  "name": "Bookly",
  "full_name": "Online Scheduling and Appointment Booking System – Bookly",
  "wordpress_org": "https://wordpress.org/plugins/bookly-responsive-appointment-booking-tool/",
  "advisories_url": "https://wpsec.com/vuln/plugin/bookly-responsive-appointment-booking-tool/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/bookly-responsive-appointment-booking-tool"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-200"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 3.7,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Low"
 },
 "affected": {
  "ranges": [
   {
    "from": "20.6",
    "from_inclusive": true,
    "to": "28.5",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 20.6 before 28.5"
  ]
 },
 "introduced_in": "20.6",
 "fixed_in": "28.5",
 "remediation": "Update to 28.5 or later.",
 "fix_released": "2026-10-06T13:25:48+00:00",
 "published": "2026-10-07T13:54:10+00:00",
 "updated": "2026-10-06T16:17:06.743240+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0544/",
  "https://plugins.svn.wordpress.org/bookly-responsive-appointment-booking-tool/tags/28.5/",
  "https://wordpress.org/plugins/bookly-responsive-appointment-booking-tool/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/bookly-responsive-appointment-booking-tool",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-07"
 }
}