PT-2026-109471 · Ladela · Online Scheduling/Appointment Booking System – Bookly

CVE-2026-103365

·

Published

2026-10-10

·

Updated

2026-10-10

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The Bookly – Online Scheduling and Appointment Booking System plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 28.4 via the classic booking form's Details step. The endpoint bookly render details is registered for both wp ajax and wp ajax nopriv, the module overrides csrfTokenValid() to always return true, and BooklyFrontendComponentsBookingInfoText::getCodes() calls UserBookingData::getCustomer() to load the persisted Customer entity keyed solely by the attacker-supplied phone (or email) with no invocation of the plugin's own customerIdentityConfirmed() predicate. When a site owner has placed the supported {client name}, {client email}, {client phone}, or {client note} placeholders into the Details step's Appearance information text, the matched customer's stored name, email, phone and internal notes are substituted into the returned HTML. This makes it possible for unauthenticated attackers who know only a registered customer's primary phone (or email) to read that customer's stored personal data.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103365

Affected Products

Online Scheduling/Appointment Booking System – Bookly