Impact
This vulnerability enables an unauthenticated attacker to read sensitive user data from the WordPress Bookly plugin. Because the plugin lacks proper input validation, crafted requests can leak internal information, exposing client details and appointment data. The weakness is an instance of inappropriate access control (CWE‑201) and directly threatens confidentiality.
Affected Systems
WordPress sites running the Bookly appointment‑booking plugin version 27.4 or earlier are affected. The vendor is Bookly, and the vulnerable product is the Bookly plugin that provides booking functionality within WordPress.
Risk and Exploitability
The CVSS score of 7.5 reflects a high impact on confidentiality. The EPSS score is below 1 %, indicating that real‑world exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote over HTTP/HTTPS, and the flaw can be exploited without authentication or additional setup, making the potential for data exposure significant.
OpenCVE Enrichment