Sceawere

Vulnerability Detail

CVE-2026-96347UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Bookly Subscriber IDOR Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Bookly
Product
Bookly
Attack Type
CWE-639 Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-30T13:17:29.693Z",
  "pubdate": "2026-09-30T13:17:29.693Z",
  "executiveSummary": "An Insecure Direct Object Reference (IDOR) vulnerability exists in the Bookly plugin for WordPress, affecting all versions up to and including 28.2.\nThis vulnerability allows authenticated users with Subscriber-level privileges to access or modify data objects that should be restricted to administrative or elevated roles.\nThe flaw stems from insufficient server-side authorization checks when processing requests that reference specific object identifiers, such as appointment IDs or user meta data.\nSuccessful exploitation enables unauthorized data retrieval or unauthorized modification of sensitive booking information.\nThe risk implication is high, as it bypasses the intended access control mechanisms defined by the plugin's architectural security model.\nExploitation requires the attacker to hold an active, low-privileged authenticated session on the target WordPress instance.\nThe vulnerability provides an attacker the capability to interact with the Bookly backend API to manipulate resources they are not explicitly authorized to manage.",
  "technicalDetails": "The vulnerability is classified as an Insecure Direct Object Reference (IDOR), located within the internal request handling mechanisms of the Bookly plugin. The root cause lies in the application's failure to perform adequate authorization verification for user-supplied identifiers submitted through POST or GET parameters.\nSpecifically, when a Subscriber-level user interacts with Bookly’s administrative or management features, the plugin backend processes requests using predictable object identifiers (e.g., IDs related to appointments, customers, or internal records) without validating that the authenticated session user possesses the requisite capabilities to perform the requested action on that specific object.\nThe attack flow follows a predictable pattern: 1) The attacker authenticates as a standard Subscriber. 2) The attacker intercepts or crafts an HTTP request targeting a Bookly functionality endpoint that accepts an object ID parameter. 3) The attacker modifies the object ID parameter to target resources belonging to other users or the system administrator. 4) The server processes the request, assuming that because the user is authenticated, they are authorized to access the requested object ID. 5) The server returns the unauthorized data or performs the requested modification (such as deleting or updating appointments) without enforcing the principle of least privilege.\nThis vulnerability is exposed over the network, as the interface is accessible via the web server hosting the WordPress instance. Because the plugin does not verify user roles against the target object's ownership or scope at the function level, the request bypasses logical security boundaries. The affected versions (up to and including 28.2) share this architectural oversight where trust is placed entirely on the presence of a valid session rather than checking permissions against the resource ID being manipulated.\nPost-exploitation impact includes unauthorized information disclosure—potentially revealing PII of other customers—and the capacity for malicious actors to disrupt booking workflows by modifying or deleting records belonging to administrators or other clients. The absence of robust access control checks across the plugin's API endpoints allows this IDOR to facilitate unauthorized administrative actions from a low-privilege context."
}
CVE-2026-96347: Bookly Subscriber IDOR Vulnerability (MEDIUM Severity, CVSS: 6.5) | Sceawere