# Bookly <= 28.4 - Unauthenticated Sensitive Information Exposure via Booking Form Info Text

- **ID:** WPSEC-2026-0544
- **Plugin:** Online Scheduling and Appointment Booking System – Bookly (`bookly-responsive-appointment-booking-tool`), https://wordpress.org/plugins/bookly-responsive-appointment-booking-tool/
- **Affected versions:** from 20.6 before 28.5
- **Fixed in:** 28.5 (Update to 28.5 or later.)
- **Severity:** Low 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-200
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/bookly-responsive-appointment-booking-tool
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0544/

## Description

The Bookly plugin for WordPress is vulnerable to Sensitive Information Exposure via the booking form info texts in versions 20.6 up to, and including, 28.4. When filling in the client placeholders, the plugin uses the stored record of an existing customer matched by the email address or phone number entered in the form, without confirming that the visitor owns that record. This makes it possible for unauthenticated attackers who know an existing customer's email address or phone number to view that customer's other stored details, such as name, phone number, address and notes, on later steps of the booking form. Exploitation requires a booking form info text to be customized to include client placeholders such as {client_address} or {client_phone}. Unless customer details verification is disabled, the attacker must also enter details that do not conflict with the stored record, such as the customer's name.

## References

- https://wpsec.com/vuln/WPSEC-2026-0544/
- https://plugins.svn.wordpress.org/bookly-responsive-appointment-booking-tool/tags/28.5/
- https://wordpress.org/plugins/bookly-responsive-appointment-booking-tool/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0544/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
