Sceawere
Vulnerability Detail
CVE-2026-96348UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Access Control Vulnerability: Bookly
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- Bookly
- Product
- Bookly
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Broken Access Control in Bookly <= 28.2 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-09-30T13:17:29.833Z",
"pubdate": "2026-09-30T13:17:29.833Z",
"executiveSummary": "Bookly versions 28.2 and earlier are susceptible to an unauthenticated broken access control vulnerability. This flaw allows unauthorized actors to bypass security restrictions and interact with sensitive application functions that should be restricted to authenticated users or administrators.\nThe vulnerability stems from improper validation of access control checks on specific endpoints within the Bookly plugin. An unauthenticated attacker can leverage this flaw to perform unauthorized actions, potentially leading to unauthorized data access, modification, or sensitive information disclosure.\nThis issue poses a significant risk to the integrity and confidentiality of the affected WordPress site's booking data and configuration. No specialized authentication is required for an attacker to exploit this vulnerability, as it manifests at the unauthenticated request level. Mitigation requires immediate update to a version of Bookly where this access control mechanism has been properly remediated.",
"technicalDetails": "The vulnerability resides within the access control implementation of the Bookly plugin. It is classified as Broken Access Control, specifically involving insufficient authorization checks on administrative or privileged endpoints.\nThe root cause is the absence or faulty implementation of access control checks (such as nonce verification or user role capability validation) on critical server-side handlers. When these handlers are invoked, the plugin fails to verify whether the incoming request originates from a legitimately authorized user session.\nExploitation occurs when an attacker crafts a malicious HTTP request targeting the vulnerable endpoints. Because the application logic does not validate the requester's identity or authorization status before processing the input, the plugin executes the requested functionality as if it were initiated by a privileged user.\nThe attack flow typically involves identifying the specific vulnerable endpoint or AJAX/REST API action within the Bookly plugin. An attacker sends a crafted POST or GET request directly to this endpoint. The vulnerable code then processes the request, bypassing security gates that should have blocked the action. This allows an attacker to interact with backend services, manipulate bookings, or extract configuration data depending on the specific function exposed.\nThis vulnerability is classified as critical because it is reachable over the network without requiring any prior authentication. The impact varies depending on the function exposed, but can range from unauthorized disclosure of sensitive booking information and user data to the unauthorized modification or deletion of appointments and plugin configuration settings. Post-exploitation, an attacker may have sufficient control over the plugin's data to cause operational disruption or facilitate further attacks against the WordPress environment."
}