Impact
The vulnerability is an insecure direct object reference that allows authenticated users with subscriber-level or higher access to override the WordPress user binding for any Bookly staff record. By supplying a manipulated 'id' or 'wp_user_id' parameter in a query string or JSON body, an attacker can reassign a staff account to another WordPress user, effectively hijacking a higher‑privileged staff member’s account. This escalation leads to the attacker gaining control of the staff member’s privileges and any associated administrative capabilities.
Affected Systems
The affected product is the WordPress plugin Online Scheduling and Appointment Booking System – Bookly, versions up to and including 28.4. All installations using these versions, and the default configuration where the bookly_gen_allow_staff_edit_profile option is enabled, are potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated subscriber‑level or higher account that has at least one staff record linked. Since the option enabling editing of staff profiles is active by default on fresh installations, many sites likely have the necessary staff‑user links in place. Attackers can trigger the exploit via the 'id' and 'wp_user_id' parameters in HTTP request URLs or JSON bodies.
OpenCVE Enrichment