WordPress · Bookly · CVE-2026-92799
**Name of the Vulnerable Software and Affected Versions**
Online Scheduling and Appointment Booking System – Bookly versions prior to 28.3
**Description**
An authorization bypass exists due to PHP Type Juggling, a condition where PHP converts a variable from one data type to another during a comparison. The `postValidateCustomer()` function uses a loose inequality operator (`!=`) to compare a session-stored verification code with the `verification code` parameter. Because the `json data` input channel uses `json decode()`, an attacker can submit a boolean `true` value, which satisfies the loose comparison against the non-zero integer code, bypassing the verification guard. This issue is exacerbated by the booking AJAX controller registering methods as `wp ajax nopriv ` handlers and overriding `csrfTokenValid()` to always return true, leaving the endpoint unauthenticated and unprotected against Cross-Site Request Forgery (CSRF). Consequently, unauthenticated attackers can bypass phone or email ownership verification to overwrite the name, email, phone, and address fields of any existing customer record, redirecting booking notifications to their own contact details.
**Recommendations**
Update Online Scheduling and Appointment Booking System – Bookly to a version newer than 28.2.