CVE · Medium

CVE-2026-12905 — Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 28.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12905 Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 28.0 Authorization Bypass Through User-Controlled Key Medium 4.3 < 28.0 28.0 2026-08-15

CVE-2026-12905

The Bookly plugin for WordPress has a security flaw in versions up to 27.7. Specifically, the plugin's Mobile Staff Cabinet API can be tricked into revealing sensitive information about appointments not assigned to the authenticated staff member. This occurs because the plugin doesn't properly verify the staff ID associated with an appointment, allowing attackers to access appointment details, including internal notes and customer information, by guessing sequential appointment IDs.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.