PT-2026-93274 · WordPress · Bookly

·

CVE-2026-89063

·

Published

2026-09-16

·

Updated

2026-09-17

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Bookly versions prior to 28.2
Description An Insecure Direct Object Reference (IDOR) exists due to missing validation on a user-controlled key. Unauthenticated attackers can enumerate customer conversations by incrementing the conversation id parameter, as these IDs are sequential integers and lack owner, user, or session identifiers. This allows attackers to read full AI booking conversation transcripts, leaking sensitive data such as names, email addresses, phone numbers, and appointment details. Additionally, attackers can inject arbitrary messages into victim conversations, which are then replayed to the Cloud AI worker along with the private history.
Recommendations Update Bookly to version 28.2 or later. As a temporary mitigation, restrict access to the functionality utilizing the conversation id parameter.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-89063

Affected Products

Bookly