PT-2026-98370 · WordPress · Bookly

·

CVE-2026-92799

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Online Scheduling and Appointment Booking System – Bookly versions prior to 28.3
Description An authorization bypass exists due to PHP Type Juggling, a condition where PHP converts a variable from one data type to another during a comparison. The postValidateCustomer() function uses a loose inequality operator (!=) to compare a session-stored verification code with the verification code parameter. Because the json data input channel uses json decode(), an attacker can submit a boolean true value, which satisfies the loose comparison against the non-zero integer code, bypassing the verification guard. This issue is exacerbated by the booking AJAX controller registering methods as wp ajax nopriv handlers and overriding csrfTokenValid() to always return true, leaving the endpoint unauthenticated and unprotected against Cross-Site Request Forgery (CSRF). Consequently, unauthenticated attackers can bypass phone or email ownership verification to overwrite the name, email, phone, and address fields of any existing customer record, redirecting booking notifications to their own contact details.
Recommendations Update Online Scheduling and Appointment Booking System – Bookly to a version newer than 28.2.

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92799

Affected Products

Bookly