Impact
The Bookly WordPress plugin, in versions prior to 28.3, does not properly verify a customer's identity before applying updates to their stored personal information. As a result, an attacker who knows a customer’s primary identifier can overwrite that customer’s name, email, and address. This lack of authentication and authorization control permits unauthorized tampering with sensitive data, potentially enabling privacy violations, fraudulent account modifications, and other harms.
Affected Systems
All installations of the Bookly WordPress plugin dated before version 28.3 are affected. Site owners should inspect their current plugin version and apply the fix if the plugin is older than 28.3.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate level of severity. Exploitation is straightforward: an unauthenticated request to the Bookly update endpoint with a known customer identifier allows the attacker to modify PII. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, but the lack of authentication combined with a known identifier gives the attacker a low barrier to attempt this modification.
OpenCVE Enrichment