CVE-2026-103365
Received Received - Intake

Sensitive Information Exposure in Bookly WordPress Plugin

Vulnerability report for CVE-2026-103365, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Wordfence

Description

The Bookly – Online Scheduling and Appointment Booking System plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 28.4 via the classic booking form's Details step. The endpoint bookly_render_details is registered for both wp_ajax and wp_ajax_nopriv, the module overrides csrfTokenValid() to always return true, and Bookly\Frontend\Components\Booking\InfoText::getCodes() calls UserBookingData::getCustomer() to load the persisted Customer entity keyed solely by the attacker-supplied phone (or email) with no invocation of the plugin's own customerIdentityConfirmed() predicate. When a site owner has placed the supported {client_name}, {client_email}, {client_phone}, or {client_note} placeholders into the Details step's Appearance information text, the matched customer's stored name, email, phone and internal notes are substituted into the returned HTML. This makes it possible for unauthenticated attackers who know only a registered customer's primary phone (or email) to read that customer's stored personal data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ladela Online Scheduling and Appointment Booking System – Bookly 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Bookly WordPress plugin allows unauthenticated attackers to access sensitive customer data by exploiting a flaw in the booking form's Details step. The plugin exposes customer information such as name, email, phone, and internal notes when specific placeholders are used in the booking form's appearance settings.

Detection Guidance

Check WordPress sites using Bookly plugin versions up to 28.4 for exposed customer data via the bookly_render_details endpoint. Inspect HTTP responses for sensitive fields like phone, email, or notes when placeholders are used in booking forms.

Impact Analysis

If you use the Bookly plugin, attackers could steal customer data like phone numbers or emails without authentication. This could lead to privacy breaches, identity theft, or misuse of personal information. The vulnerability affects any site owner using the plugin with the vulnerable booking form.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized access to personal data. GDPR requires protecting personal data, and HIPAA mandates safeguarding health-related information. The exposure of customer details without consent or authentication could result in legal penalties and compliance failures.

Mitigation Strategies

Update the Bookly plugin to the latest version immediately. Disable the bookly_render_details endpoint if not required. Review and restrict access to customer data fields in booking forms.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103365. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart