Impact
The Bookly plugin for WordPress contains an insecure direct object reference vulnerability in all releases up to 28.1 that allows an unauthenticated user to pass a 'conversation_id' parameter. Because the plugin stores AI booking conversations without user or session identifiers and the IDs are simple sequential integers, an attacker can read any customer’s booking transcript, leaking names, email addresses, phone numbers and appointment details. The same flaw also permits conversation, which are then sent to the Cloud AI worker along with the private history, potentially altering booking interactions.
Affected Systems
The affected product is the Bookly online scheduling and appointment booking plugin from ladela, all versions up to and including 28.1. No other vendors or product variants are listed in the CVE record.
Risk and Exploitability
The vulnerability is rated with a CVSS score of 7.5, indicating moderate to high severity. The EPSS score is below 1 %, reflecting a very low current exploitation probability, and the flaw is not catalogued in the CISA KEV list. Exploitation requires only crafting a web request to the Ajax endpoint that handles the IDs are sequential. The flaw can be abused without further authentication or privileged access and covers any user who has used the AI booking assistant.
OpenCVE Enrichment