Impact
The vulnerability stems from the Online Scheduling and Appointment Booking System failing to validate that appointment and payment records requested via AJAX belong to the authenticated staff member. This flaw lets an attacker with a staff-level role view, alter, or delete any staff member’s appointments and associated payments, thereby compromising confidentiality, integrity, and availability of sensitive customer data.
Affected Systems
Bookly, a WordPress plugin for online scheduling, is affected in any installation running a version prior to 28.3. The plugin is deployed on WordPress sites worldwide and is used by organizations that rely on staff accounts to manage customer bookings and payments.
Risk and Exploitability
The vulnerability is exploitable through any staff account, which typically has privileged access. Although the CVSS score is not provided and EPSS data is unavailable, the lack of a protective check in a trusted role elevates the risk. No public exploits or KEV listing exist, but the potential damage makes remediation a priority.
OpenCVE Enrichment