CVE-2026-104898Medium· 6.8▾ SunlitThe Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.4 via the 'id, wp_user_id' parameter due to missing validation …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.4 via the 'id, wp_user_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the WordPress account binding of any Bookly staff record, including those owned by administrators, effectively hijacking a higher-privileged staff member's account association and escalating privileges. Exploitation requires the attacking user to be linked to at least one Bookly staff record, which occurs by default whenever an admin enables the bookly_gen_allow_staff_edit_profile option (active on fresh installs) and links a WordPress user to a staff entry.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-12288Medium· 4.3A vulnerability was detected in Bdtask Pharmacy Management System up to 9.4
CVE-2025-12283Medium· 4.3A security flaw has been discovered in code-projects Client Details System 1.0
CVE-2021-46416High· 8.1Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.
CVE-2025-14459High· 8.5A flaw was found in KubeVirt Containerized Data Importer (CDI)
CVE-2025-11519Medium· 4.3The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the /wp-json/optml/v1/move…
CVE-2025-11517High· 7.5The Event Tickets and Registration plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 5.26.5