PT-2026-73082 · WordPress · Bookly
CVE-2026-12905
·
Published
2026-08-16
·
Updated
2026-08-17
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Bookly versions prior to 27.8
Description
An Insecure Direct Object Reference exists in the Mobile Staff Cabinet API via the
appointment() function. The issue occurs because the handler loads an appointment using the params[id] variable without verifying if the appointment's staff id matches the authenticated staff member. This allows authenticated attackers with staff-level mobile cabinet access to read appointment details belonging to other staff members by enumerating sequential IDs. Exposed information includes internal notes and the customer appointments collection, which contains customer full names, emails, phone numbers, notes, custom fields, extras, payment totals, payment types, and payment statuses. The affected API endpoint is identified by resource=appointment and action=bookly mobile staff cabinet.Recommendations
Update Bookly to version 27.8 or later.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bookly