WordPress · Bookly · CVE-2026-89063
**Name of the Vulnerable Software and Affected Versions**
Bookly versions prior to 28.2
**Description**
An Insecure Direct Object Reference (IDOR) exists due to missing validation on a user-controlled key. Unauthenticated attackers can enumerate customer conversations by incrementing the `conversation id` parameter, as these IDs are sequential integers and lack owner, user, or session identifiers. This allows attackers to read full AI booking conversation transcripts, leaking sensitive data such as names, email addresses, phone numbers, and appointment details. Additionally, attackers can inject arbitrary messages into victim conversations, which are then replayed to the Cloud AI worker along with the private history.
**Recommendations**
Update Bookly to version 28.2 or later.
As a temporary mitigation, restrict access to the functionality utilizing the `conversation id` parameter.