Bookly is a widely used WordPress plugin designed to facilitate appointment booking for service-based businesses such as salons, doctors' offices, and consultants. With its customizable booking forms, Bookly is popular among small to medium-sized enterprises for streamlining scheduling processes. The plugin also integrates with various payment gateways, allowing businesses to manage transactions directly through their websites. Bookly's ease of use and automated reminders make it a favored choice for enhancing customer experience. Furthermore, this plugin supports multiple languages and time zones, making it versatile for a global customer base. Organizations using WordPress often choose Bookly to automate and improve their scheduling operations efficiently.
The Insecure Direct Object Reference (IDOR) vulnerability in Bookly allows unauthenticated attackers to access sensitive customer data. This vulnerability stems from a lack of validation on the "conversation_id" parameter in the plugin's code. Consequently, it enables unauthorized individuals to both read confidential information and inject messages into ongoing booking conversations. By exploiting this flaw, attackers can compromise the privacy and integrity of data. This type of vulnerability is particularly concerning because it requires no authentication, making it easily exploitable by anyone with internet access. Addressing such vulnerabilities is critical in maintaining the trust and privacy of users' data.
Technical details reveal that the vulnerability lies in the interaction with the "conversation_id" parameter within Bookly's functionality. Specifically, the vulnerable endpoint is accessed without proper authentication checks, which should validate user access based on their session. Attackers can manipulate requests to view or alter booking conversations, facilitated by the exposure of the "conversation_id" in requests. The vulnerability is impactful where sensitive customer information within the conversation is compromised. The issue persists across versions 28.1 and earlier, highlighting the need for a robust access control mechanism. This vulnerability does not require privileges or user interaction, increasing its potential for exploitation.
If exploited, this vulnerability may lead to unauthorized access to private booking details, undermining user privacy. Malicious individuals can utilize this access to alter conversation data, potentially leading to misinformation or fraudulent activities. The breach of data confidentiality can result in identity theft, financial loss, or reputational damage to the business using the plugin. Customers affected by such vulnerabilities might lose trust in the enterprise, affecting customer retention adversely. The unchecked data injection can have further implications if attackers choose to manipulate booking confirmations or reminders. Data integrity is compromised, causing operational disruptions and necessitating immediate remediation to prevent such incidents.
REFERENCES
- https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bookly-responsive-appointment-booking-tool/online-scheduling-and-appointment-booking-system-281-insecure-direct-object-reference-to-unauthenticated-sensitive-data-access-and-message-injection-via-conversation-id-parameter
- https://www.cve.org/CVERecord?id=CVE-2026-89063
- Update Bookly to a version later than 28.1 to patch the vulnerability.
- Implement robust input validation and access controls for sensitive data parameters.
- Regularly audit the security settings and configurations of WordPress plugins.
- Monitor logs to detect any suspicious activity or unauthorized access to booking data.
- Consider using web application firewalls to provide an additional layer of security.
Get AI-powered remediation steps tailored to your asset.
Try AI Solutions →