PT-2026-93274 · WordPress · Bookly
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Bookly versions prior to 28.2
Description
An Insecure Direct Object Reference (IDOR) exists due to missing validation on a user-controlled key. Unauthenticated attackers can enumerate customer conversations by incrementing the
conversation id parameter, as these IDs are sequential integers and lack owner, user, or session identifiers. This allows attackers to read full AI booking conversation transcripts, leaking sensitive data such as names, email addresses, phone numbers, and appointment details. Additionally, attackers can inject arbitrary messages into victim conversations, which are then replayed to the Cloud AI worker along with the private history.Recommendations
Update Bookly to version 28.2 or later.
As a temporary mitigation, restrict access to the functionality utilizing the
conversation id parameter.Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bookly