Vulnerabilities / Bookly
Bookly vulnerabilities
Advisories WPSec published for Online Scheduling and Appointment Booking System – Bookly. Other sources may list more. Its attack surface: Bookly on WPSec AttackSurface.
| Published | ID | Vulnerability | Severity | Fixed in |
|---|---|---|---|---|
| 2026-10-07 | WPSEC-2026-0544 | Bookly <= 28.4 - Unauthenticated Sensitive Information Exposure via Booking Form Info Text | Low 3.7 | 28.5 |
| 2026-10-07 | WPSEC-2026-0543 | Bookly <= 28.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Staff Profile Update | Medium 5.4 | 28.5 |
License: CC BY 4.0