2026-09-27 6:0CVE-2026-86839WPScan
PUBLISHED5.2

Bookly < 28.3 - Staff+ Appointment and Payment Disclosure, Modification and Deletion via IDOR

The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff members' appointments and payments, including the associated customer's personal information.

Problem type

  • CWE-639 Authorization Bypass Through User-Controlled Key

Affected products

Unknown

Online Scheduling and Appointment Booking System

< 28.3 - AFFECTED

References

GitHub Security Advisories

GHSA-36wf-cx88-gfjh

The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not...

https://github.com/advisories/GHSA-36wf-cx88-gfjh

The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff members' appointments and payments, including the associated customer's personal information.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-86839
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-86839",
    "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
    "assignerShortName": "WPScan",
    "dateUpdated": "2026-09-27T06:00:20.309Z",
    "dateReserved": "2026-09-08T14:43:22.104Z",
    "datePublished": "2026-09-27T06:00:20.309Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "shortName": "WPScan",
        "dateUpdated": "2026-09-27T06:00:20.309Z"
      },
      "title": "Bookly < 28.3 - Staff+ Appointment and Payment Disclosure, Modification and Deletion via IDOR",
      "descriptions": [
        {
          "lang": "en",
          "value": "The Online Scheduling and Appointment Booking System  WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff members' appointments and payments, including the associated customer's personal information."
        }
      ],
      "affected": [
        {
          "vendor": "Unknown",
          "product": "Online Scheduling and Appointment Booking System",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "semver",
              "lessThan": "28.3"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-639 Authorization Bypass Through User-Controlled Key",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/3ab8b879-3ef7-4aa4-8620-1bde99697dcb/",
          "tags": [
            "exploit",
            "vdb-entry",
            "technical-description"
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Vũ Quang Huy",
          "type": "finder"
        },
        {
          "lang": "en",
          "value": "WPScan",
          "type": "coordinator"
        }
      ]
    }
  }
}