PT-2026-73082 · WordPress · Bookly

CVE-2026-12905

·

Published

2026-08-16

·

Updated

2026-08-17

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Bookly versions prior to 27.8
Description An Insecure Direct Object Reference exists in the Mobile Staff Cabinet API via the appointment() function. The issue occurs because the handler loads an appointment using the params[id] variable without verifying if the appointment's staff id matches the authenticated staff member. This allows authenticated attackers with staff-level mobile cabinet access to read appointment details belonging to other staff members by enumerating sequential IDs. Exposed information includes internal notes and the customer appointments collection, which contains customer full names, emails, phone numbers, notes, custom fields, extras, payment totals, payment types, and payment statuses. The affected API endpoint is identified by resource=appointment and action=bookly mobile staff cabinet.
Recommendations Update Bookly to version 27.8 or later.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12905

Affected Products

Bookly