PT-2026-98370 · WordPress · Bookly
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Online Scheduling and Appointment Booking System – Bookly versions prior to 28.3
Description
An authorization bypass exists due to PHP Type Juggling, a condition where PHP converts a variable from one data type to another during a comparison. The
postValidateCustomer() function uses a loose inequality operator (!=) to compare a session-stored verification code with the verification code parameter. Because the json data input channel uses json decode(), an attacker can submit a boolean true value, which satisfies the loose comparison against the non-zero integer code, bypassing the verification guard. This issue is exacerbated by the booking AJAX controller registering methods as wp ajax nopriv handlers and overriding csrfTokenValid() to always return true, leaving the endpoint unauthenticated and unprotected against Cross-Site Request Forgery (CSRF). Consequently, unauthenticated attackers can bypass phone or email ownership verification to overwrite the name, email, phone, and address fields of any existing customer record, redirecting booking notifications to their own contact details.Recommendations
Update Online Scheduling and Appointment Booking System – Bookly to a version newer than 28.2.
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bookly