Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 11 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 10 Oct 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Bookly – Online Scheduling and Appointment Booking System plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 28.4 via the classic booking form's Details step. The endpoint bookly_render_details is registered for both wp_ajax and wp_ajax_nopriv, the module overrides csrfTokenValid() to always return true, and Bookly\Frontend\Components\Booking\InfoText::getCodes() calls UserBookingData::getCustomer() to load the persisted Customer entity keyed solely by the attacker-supplied phone (or email) with no invocation of the plugin's own customerIdentityConfirmed() predicate. When a site owner has placed the supported {client_name}, {client_email}, {client_phone}, or {client_note} placeholders into the Details step's Appearance information text, the matched customer's stored name, email, phone and internal notes are substituted into the returned HTML. This makes it possible for unauthenticated attackers who know only a registered customer's primary phone (or email) to read that customer's stored personal data. | |
| Title | Online Scheduling and Appointment Booking System <= 28.4 - Unauthenticated Sensitive Information Exposure in 'phone' Parameter to bookly_render_details | |
| Weaknesses | CWE-200 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-10-11T16:55:19.933Z
Reserved: 2026-09-30T12:59:43.597Z
Link: CVE-2026-103365
Updated: 2026-10-11T16:46:24.772Z
Status : Received
Published: 2026-10-10T04:18:08.297
Modified: 2026-10-11T17:16:57.907
Link: CVE-2026-103365
No data.
OpenCVE Enrichment
Updated: 2026-10-10T04:30:17Z