Description
The Bookly – Online Scheduling and Appointment Booking System plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 28.4 via the classic booking form's Details step. The endpoint bookly_render_details is registered for both wp_ajax and wp_ajax_nopriv, the module overrides csrfTokenValid() to always return true, and Bookly\Frontend\Components\Booking\InfoText::getCodes() calls UserBookingData::getCustomer() to load the persisted Customer entity keyed solely by the attacker-supplied phone (or email) with no invocation of the plugin's own customerIdentityConfirmed() predicate. When a site owner has placed the supported {client_name}, {client_email}, {client_phone}, or {client_note} placeholders into the Details step's Appearance information text, the matched customer's stored name, email, phone and internal notes are substituted into the returned HTML. This makes it possible for unauthenticated attackers who know only a registered customer's primary phone (or email) to read that customer's stored personal data.
Published: 2026-10-10
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Sensitive Data Exposure
Action: Patch
AI Analysis

Impact

The vulnerability in Bookly – Online Scheduling and Appointment Booking System allows an unauthenticated attacker to read the personal data of registered customers. The plugin registers the endpoint bookly_render_details for both loggedin and non‑loggedin AJAX requests and deliberately disables CSRF protection for this endpoint. When a booking’s Details step contains placeholders such as {client_name}, {client_email}, {client_phone}, or {client_note}, the plugin retrieves the customer record keyed solely by the attacker‑supplied phone number or email address and substitutes the stored name, email, phone, and internal notes into the returned HTML. This flaw amounts to a classic Sensitive Information Exposure issue (CWE-200) because unauthorized parties can learn a customer’s private data with no authentication or other privileges.

Affected Systems

WordPress sites using the ladela Online Scheduling and Appointment Booking System – Bookly plugin, versions up to and including 28.4 are affected.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. EPSS data is unavailable, and the vulnerability is not in CISA’s KEV catalog, but it is exploitable by simply knowing a customer’s phone number or email and sending a request to the bookly_render_details endpoint. No credentials or elevated privileges are required, making the attack surface wide and the likelihood of exploitation potentially significant if attackers can discover customer contact information.

Generated by OpenCVE AI on October 10, 2026 at 04:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Bookly to version 28.5 or later to address the exposed information retrieval bug.
  • Remove any {client_name}, {client_email}, {client_phone}, or {client_note} placeholders from the Details step’s appearance text so that personal data is not injected into the response.
  • Configure a security solution to restrict unauthenticated access to the bookly_render_details AJAX endpoint, such as dropping the wp_ajax_nopriv registration or blocking the route with a firewall or plugin.

Generated by OpenCVE AI on October 10, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
Description The Bookly – Online Scheduling and Appointment Booking System plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 28.4 via the classic booking form's Details step. The endpoint bookly_render_details is registered for both wp_ajax and wp_ajax_nopriv, the module overrides csrfTokenValid() to always return true, and Bookly\Frontend\Components\Booking\InfoText::getCodes() calls UserBookingData::getCustomer() to load the persisted Customer entity keyed solely by the attacker-supplied phone (or email) with no invocation of the plugin's own customerIdentityConfirmed() predicate. When a site owner has placed the supported {client_name}, {client_email}, {client_phone}, or {client_note} placeholders into the Details step's Appearance information text, the matched customer's stored name, email, phone and internal notes are substituted into the returned HTML. This makes it possible for unauthenticated attackers who know only a registered customer's primary phone (or email) to read that customer's stored personal data.
Title Online Scheduling and Appointment Booking System <= 28.4 - Unauthenticated Sensitive Information Exposure in 'phone' Parameter to bookly_render_details
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T03:26:45.710Z

Reserved: 2026-09-30T12:59:43.597Z

Link: CVE-2026-103365

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T04:18:08.297

Modified: 2026-10-10T04:18:08.297

Link: CVE-2026-103365

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T04:30:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor