CVE-2026-86839
Received Received - Intake

Unauthorized Data Access in WordPress Appointment Booking System

Vulnerability report for CVE-2026-86839, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: WPScan

Description

The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff members' appointments and payments, including the associated customer's personal information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-27
AI Q&A
2026-09-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
bookly bookly to 28.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Direct Object Reference (IDOR) flaw in the WordPress plugin Bookly versions before 28.3. It allows authenticated staff-level users to view, modify, or delete appointments and payments belonging to other staff members without proper verification. This includes access to customer personal information.

Detection Guidance

To detect this vulnerability, check if your WordPress site uses the Bookly plugin version prior to 28.3. Log in as a staff-level user and attempt to access, modify, or delete appointments or payments not assigned to you. Monitor for unauthorized changes to customer data or appointment records.

Impact Analysis

If you use Bookly with a staff account, an attacker with a staff account could access, alter, or delete your appointments and payments. They could also view or steal customer personal data, leading to privacy breaches and potential misuse of sensitive information.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized access to personal data. GDPR requires protecting personal data, and HIPAA mandates safeguarding health-related information. A breach could result in legal penalties and reputational damage.

Mitigation Strategies

Immediately update the Bookly plugin to version 28.3 or later. Review all staff accounts for suspicious activity, especially unauthorized access to appointments or payments. Restrict staff-level permissions to the minimum required for their roles.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86839. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart