CVE Database /
CVE-2026-12905
CVE · Medium
CVE-2026-12905 — Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 28.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-12905
|
Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 28.0 |
Authorization Bypass Through User-Controlled Key |
Medium
4.3
|
< 28.0
|
28.0 |
2026-08-15 |
—
|
CVE-2026-12905
The Bookly plugin for WordPress has a security flaw in versions up to 27.7. Specifically, the plugin's Mobile Staff Cabinet API can be tricked into revealing sensitive information about appointments not assigned to the authenticated staff member. This occurs because the plugin doesn't properly verify the staff ID associated with an appointment, allowing attackers to access appointment details, including internal notes and customer information, by guessing sequential appointment IDs.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings