PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Sep 26, 2026

CVE-2026-89063 Scanner

CVE-2026-89063 Scanner - Insecure Direct Object Reference vulnerability in Bookly

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
1
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.
Description

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.1 via the 'conversation_id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to read the full AI booking conversation transcript of any customer — leaking names, email addresses, phone numbers, and appointment details echoed by the assistant — and inject arbitrary messages into any victim conversation that are subsequently replayed to the Cloud AI worker along with the full private history. Because AI conversations are stored with no owner, user, or session identifier and conversation IDs are sequential integers, an unauthenticated attacker can enumerate all customer conversations simply by incrementing the conversation_id parameter.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Online Scheduling and Appointment Booking System – Booklyby ladela
0
Updated Sep 26, 2026View on NVD →
Detail

Bookly is a widely used WordPress plugin designed to facilitate appointment booking for service-based businesses such as salons, doctors' offices, and consultants. With its customizable booking forms, Bookly is popular among small to medium-sized enterprises for streamlining scheduling processes. The plugin also integrates with various payment gateways, allowing businesses to manage transactions directly through their websites. Bookly's ease of use and automated reminders make it a favored choice for enhancing customer experience. Furthermore, this plugin supports multiple languages and time zones, making it versatile for a global customer base. Organizations using WordPress often choose Bookly to automate and improve their scheduling operations efficiently.

The Insecure Direct Object Reference (IDOR) vulnerability in Bookly allows unauthenticated attackers to access sensitive customer data. This vulnerability stems from a lack of validation on the "conversation_id" parameter in the plugin's code. Consequently, it enables unauthorized individuals to both read confidential information and inject messages into ongoing booking conversations. By exploiting this flaw, attackers can compromise the privacy and integrity of data. This type of vulnerability is particularly concerning because it requires no authentication, making it easily exploitable by anyone with internet access. Addressing such vulnerabilities is critical in maintaining the trust and privacy of users' data.

Technical details reveal that the vulnerability lies in the interaction with the "conversation_id" parameter within Bookly's functionality. Specifically, the vulnerable endpoint is accessed without proper authentication checks, which should validate user access based on their session. Attackers can manipulate requests to view or alter booking conversations, facilitated by the exposure of the "conversation_id" in requests. The vulnerability is impactful where sensitive customer information within the conversation is compromised. The issue persists across versions 28.1 and earlier, highlighting the need for a robust access control mechanism. This vulnerability does not require privileges or user interaction, increasing its potential for exploitation.

If exploited, this vulnerability may lead to unauthorized access to private booking details, undermining user privacy. Malicious individuals can utilize this access to alter conversation data, potentially leading to misinformation or fraudulent activities. The breach of data confidentiality can result in identity theft, financial loss, or reputational damage to the business using the plugin. Customers affected by such vulnerabilities might lose trust in the enterprise, affecting customer retention adversely. The unchecked data injection can have further implications if attackers choose to manipulate booking confirmations or reminders. Data integrity is compromised, causing operational disruptions and necessitating immediate remediation to prevent such incidents.

REFERENCES

Solution Advice
Remediation:
  • Update Bookly to a version later than 28.1 to patch the vulnerability.
  • Implement robust input validation and access controls for sensitive data parameters.
  • Regularly audit the security settings and configurations of WordPress plugins.
  • Monitor logs to detect any suspicious activity or unauthorized access to booking data.
  • Consider using web application firewalls to provide an additional layer of security.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.