Description
The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversation actions, allowing any unauthenticated visitor to read another visitor's assistant messages and to inject messages into their in-progress conversation.
Published: 2026-09-19
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized disclosure and injection of AI assistant conversation data
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows an unauthenticated visitor to read messages from another user's AI booking‑assistant conversation and to inject messages into an in‑progress conversation. This provides the attacker with confidential user information and the ability to alter the intended conversation flow, potentially leading to misinformation or user manipulation.

Affected Systems

The affected product is the Online Scheduling and Appointment Booking System WordPress plugin, versions prior to 28.2. The plugin does not enforce ownership checks on its AI conversation actions, enabling the flaw across all earlier releases of this plugin. No other vendors or products are listed in the CNA data.

Risk and Exploitability

High‑level risk assessment: The flaw is an unauthenticated IDOR that permits reading and injecting AI assistant conversation content. The CVSS score of 4.8 classifies it as low severity. The EPSS score is below 1%, indicating a low predicted likelihood of mass exploitation. The vulnerability is not listed in the CISA KEV catalog. Because any unauthenticated web user can send a request to the conversation endpoint with a target user’s conversation ID, they can retrieve or alter messages in real time. The attack requires no special credentials or analytical skills; it merely involves crafting a suitable HTTP request. While the impact does not allow full system compromise, it leaks potentially private AI conversation data and could disrupt legitimate booking interactions.

Generated by OpenCVE AI on September 20, 2026 at 00:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the plugin to version 28.2 or later
  • Implement an ownership check before processing unauthenticated conversation actions
  • Monitor server logs for unexpected conversation access or message injection attempts

Generated by OpenCVE AI on September 20, 2026 at 00:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Bookly
Bookly bookly
Wordpress
Wordpress wordpress
Vendors & Products Bookly
Bookly bookly
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-613

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Sat, 19 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-613
CWE-639

Sat, 19 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversation actions, allowing any unauthenticated visitor to read another visitor's assistant messages and to inject messages into their in-progress conversation.
Title Bookly < 28.2 - Unauthenticated AI Assistant Conversation Disclosure and Message Injection via IDOR
References

Subscriptions

Bookly Bookly
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-19T13:18:25.713Z

Reserved: 2026-09-15T08:36:37.677Z

Link: CVE-2026-91847

cve-icon Vulnrichment

Updated: 2026-09-19T13:11:26.527Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T07:16:33.480

Modified: 2026-09-21T13:34:57.127

Link: CVE-2026-91847

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:00:12Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key