VulnSea

online_scheduling_and_appointment_booking_system_bookly vulnerabilities

CVEs whose affected-version data names the online_scheduling_and_appointment_booking_system_bookly package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-92799Medium· 5.3
2d ago

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in all versions up to, and including, 28.2

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in all versions up to, and including, 28.2. This is due to the `postValidateCustomer()` functi…

▾ Sunlitladela · Online Scheduling and Appointment Booking System – BooklyEPSS 0.32%via NVD
CVE-2026-93399Critical· 9.1PoC
2d ago

The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX ac…

The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX ac…

▾ Abyssalladela · Online Scheduling and Appointment Booking System – BooklyEPSS 0.37%via NVD
CVE-2026-89063High· 7.5PoC
1w ago

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.1 via the 'conversation_id' parameter due to missing validation…

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.1 via the 'conversation_id' parameter due to missing validation…

▾ Midnightladela · Online Scheduling and Appointment Booking System – BooklyEPSS 1.6%via NVD
CVE-2026-2520Medium· 5.4
2w ago

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'updateAddon' function in all versions up to, and including, 2…

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'updateAddon' function in all versions up to, and including, 2…

▾ Sunlitladela · Online Scheduling and Appointment Booking System – BooklyEPSS 0.21%via NVD
online_scheduling_and_appointment_booking_system_bookly vulnerabilities (CVEs) · VulnSea