Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesOnline Scheduling and Appointment Booking System

Online Scheduling and Appointment Booking System vulnerabilities

Online Scheduling and Appointment Booking System has 15 known vulnerabilities in this database. The most recent published record is dated 27 Sep 2026.

Known vulnerabilities
15
Active installs
60,000+
Latest version
28.4
Last updated
1 Oct 2026
Most recent
27 Sep 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
PHP object injection
CVE-2026-86841
Medium 4.7Before 28.3Fixed in 28.310 d ago
Broken access control
CVE-2026-86839
Low 3.8Before 28.3Fixed in 28.310 d ago
Broken access control
CVE-2026-93399
Critical 9.1Up to 28.2Fixed in a later version (latest 28.4)12 d ago
Cross-site request forgery (CSRF)
CVE-2026-92799
Medium 5.3Up to 28.2Fixed in a later version (latest 28.4)12 d ago
Broken access control
CVE-2026-91847
Medium 4.8Before 28.2Fixed in 28.219 Sep 2026
Broken access control
CVE-2026-89063
High 7.5Up to 28.1Fixed in a later version (latest 28.4)16 Sep 2026
Broken access control
CVE-2026-2520
Medium 5.4Up to 27.2Fixed in a later version (latest 28.4)8 Sep 2026
Cross-site scripting (XSS)
CVE-2026-13424
High 7.2Up to 27.7Fixed in a later version (latest 28.4)16 Aug 2026
Broken access control
CVE-2026-12905
Medium 4.3Up to 27.7Fixed in a later version (latest 28.4)16 Aug 2026
SQL injection
CVE-2026-13395
High 8.6Before 27.8Fixed in 27.830 Jul 2026
SQL injection
CVE-2026-14516
High 7.5Up to 27.5Fixed in a later version (latest 28.4)28 Jul 2026
Cross-site scripting (XSS)
CVE-2026-5513
High 7.2Up to 27.2Fixed in a later version (latest 28.4)13 Jun 2026
Security weakness
CVE-2026-2519
Medium 5.3Up to 27.0Fixed in a later version (latest 28.4)9 Apr 2026
Cross-site scripting (XSS)
CVE-2024-5584
Medium 6.4Up to 23.2Fixed in a later version (latest 28.4)11 Jun 2024
Cross-site scripting (XSS)
CVE-2018-6891
Medium 6.1Before 14.5Fixed in 14.511 Feb 2018
Read the published descriptions
CVE-2026-86841, 27 Sep 2026
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged maintenance feature to administrators, allowing users granted a custom booking-management capability, which an administrator must explicitly assign, to inject arbitrary PHP objects, overwrite privileged site options, and read stored integration secrets. CVE record
CVE-2026-86839, 27 Sep 2026
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff members' appointments and payments, including the associated customer's personal information. CVE record
CVE-2026-93399, 25 Sep 2026
The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX actions. This is due to the 'bookly_get_form_id' handler blindly storing the attacker-controlled 'order_id' from the submitted form_data into a new booking session, which the 'bookly_render_complete' handler then trusts to look up and return the corresponding Order's secret token without verifying that the current session created that order. This makes it possible for unauthenticated attackers to enumerate sequential order IDs, disclose other customers' order tokens, retrieve calendar/appointment information via 'bookly_add_to_calendar' and permanently delete arbitrary non-completed bookings via 'bookly_rollback_order', which cascade-deletes the customer_appointment and (when no other customers are attached) the underlying appointment. CVE record
CVE-2026-92799, 25 Sep 2026
The Online Scheduling and Appointment Booking System - Bookly plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in all versions up to, and including, 28.2. This is due to the `postValidateCustomer()` function using a loose PHP inequality operator (`!=`) to compare the session-stored one-time verification code against the attacker-supplied `verification_code` parameter - a flaw that is further exposed by the booking AJAX controller registering all its methods as `wp_ajax_nopriv_` handlers and unconditionally overriding `csrfTokenValid()` to return true, leaving the endpoint both unauthenticated and CSRF-unprotected. This makes it possible for unauthenticated attackers to bypass the phone/email ownership verification step and overwrite the name, email, phone, and address fields of any arbitrary existing Bookly customer record, redirecting that customer's booking notifications to attacker-controlled contact details. The bypass is achievable because the `json_data` input channel decodes input via `json_decode()`, which preserves real PHP types and causes the `wp_kses` filter to leave non-string values such as the JSON boolean `true` untouched; submitting `true` as the `verification_code` satisfies the loose comparison against the session's non-zero integer code (generated by `mt_rand(100000, 999999)`), causing `true != <non-zero int>` to evaluate as `false` and the guard to be bypassed. CVE record
CVE-2026-91847, 19 Sep 2026
The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversation actions, allowing any unauthenticated visitor to read another visitor's assistant messages and to inject messages into their in-progress conversation. CVE record
CVE-2026-89063, 16 Sep 2026
The Online Scheduling and Appointment Booking System - Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.1 via the 'conversation_id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to read the full AI booking conversation transcript of any customer - leaking names, email addresses, phone numbers, and appointment details echoed by the assistant - and inject arbitrary messages into any victim conversation that are subsequently replayed to the Cloud AI worker along with the full private history. Because AI conversations are stored with no owner, user, or session identifier and conversation IDs are sequential integers, an unauthenticated attacker can enumerate all customer conversations simply by incrementing the conversation_id parameter. CVE record
CVE-2026-2520, 8 Sep 2026
The Online Scheduling and Appointment Booking System - Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'updateAddon' function in all versions up to, and including, 27.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update any plugin with a main file of 'main.php' to its latest version. CVE record
CVE-2026-13424, 16 Aug 2026
The Online Scheduling and Appointment Booking System - Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action in all versions up to, and including, 27.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injection point is the bookly_speed_up_update_addons AJAX action, which is registered as wp_ajax_nopriv_* and therefore reachable without authentication; the payload is stored verbatim in the bookly_log.details column when a request is submitted without a valid signature, and executes when an administrator later views the Diagnostics → Logs page. CVE record
CVE-2026-12905, 16 Aug 2026
The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via the appointment() method of the Mobile Staff Cabinet API (resource=appointment, action=bookly_mobile_staff_cabinet) in frontend/modules/mobile_staff_cabinet/api/handlers/Handler1_0.php. This is due to the handler loading an Appointment by the attacker-supplied params[id] without verifying that the appointment's staff_id matches the authenticated staff member, whereas sibling operations (deleteAppointment, saveAppointment, appointments list) correctly scope to $this->staff->getId() when $this->role === ROLE_STAFF. This makes it possible for authenticated attackers, with staff-level mobile cabinet access (any valid access_key token bound to a Staff entity), to read appointment details - including the internal note and the full customer_appointments collection (customer full_name, email, phone, notes, custom_fields, extras, payment_total, payment_type, payment_status) - belonging to other staff members by enumerating sequential appointment IDs. CVE record
CVE-2026-13395, 30 Jul 2026
The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data such as password hashes from the database. CVE record
CVE-2026-14516, 28 Jul 2026
The Online Scheduling and Appointment Booking System - Bookly plugin for WordPress is vulnerable to time-based SQL Injection via the 'staff_ids' parameter in all versions up to, and including, 27.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires a two-request chain: an attacker first calls the unauthenticated bookly_get_form_id action to seed a booking session carrying malicious staff_ids values, then triggers bookly_render_time to cause the tainted array to reach the vulnerable query; CSRF/nonce validation is absent on both endpoints, meaning this chain can be initiated cross-site. CVE record
CVE-2026-5513, 13 Jun 2026
The Online Scheduling and Appointment Booking System - Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-customer-full-name' cookie in versions up to, and including, 27.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires 'Remember personal information in cookies' setting to be enabled (disabled by default). CVE record
CVE-2026-2519, 9 Apr 2026
The Online Scheduling and Appointment Booking System - Bookly plugin for WordPress is vulnerable to price manipulation via the 'tips' parameter in all versions up to, and including, 27.0. This is due to the plugin trusting a user-supplied input without server-side validation against the configured price. This makes it possible for unauthenticated attackers to submit a negative number to the 'tips' parameter, causing the total price to be reduced to zero. CVE record
CVE-2024-5584, 11 Jun 2024
The WordPress Online Booking and Scheduling Plugin - Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Color Profile parameter in all versions up to, and including, 23.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with the staff member role and Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2018-6891, 11 Feb 2018
Bookly #1 WordPress Booking Plugin Lite before 14.5 has XSS via a jQuery.ajax request to ng-payment_details_dialog.js. CVE record

What to do if you run Online Scheduling and Appointment Booking System

If you run Online Scheduling and Appointment Booking System, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Online Scheduling and Appointment Booking System vulnerabilities

Free. We email you when a new vulnerability is published for Online Scheduling and Appointment Booking System, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support