Impact
The vulnerability in Bookly – Online Scheduling and Appointment Booking System allows an unauthenticated attacker to read the personal data of registered customers. The plugin registers the endpoint bookly_render_details for both loggedin and non‑loggedin AJAX requests and deliberately disables CSRF protection for this endpoint. When a booking’s Details step contains placeholders such as {client_name}, {client_email}, {client_phone}, or {client_note}, the plugin retrieves the customer record keyed solely by the attacker‑supplied phone number or email address and substitutes the stored name, email, phone, and internal notes into the returned HTML. This flaw amounts to a classic Sensitive Information Exposure issue (CWE-200) because unauthorized parties can learn a customer’s private data with no authentication or other privileges.
Affected Systems
WordPress sites using the ladela Online Scheduling and Appointment Booking System – Bookly plugin, versions up to and including 28.4 are affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS data is unavailable, and the vulnerability is not in CISA’s KEV catalog, but it is exploitable by simply knowing a customer’s phone number or email and sending a request to the bookly_render_details endpoint. No credentials or elevated privileges are required, making the attack surface wide and the likelihood of exploitation potentially significant if attackers can discover customer contact information.
OpenCVE Enrichment