HomeWordPress vulnerabilitiesOnline Scheduling and Appointment Booking System
Online Scheduling and Appointment Booking System vulnerabilities
Online Scheduling and Appointment Booking System has 15 known vulnerabilities in this database. The most recent published record is dated 27 Sep 2026.
- Known vulnerabilities
- 15
- Active installs
- 60,000+
- Latest version
- 28.4
- Last updated
- 1 Oct 2026
- Most recent
- 27 Sep 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| PHP object injection CVE-2026-86841 | Medium 4.7 | Before 28.3 | Fixed in 28.3 | 10 d ago |
| Broken access control CVE-2026-86839 | Low 3.8 | Before 28.3 | Fixed in 28.3 | 10 d ago |
| Broken access control CVE-2026-93399 | Critical 9.1 | Up to 28.2 | Fixed in a later version (latest 28.4) | 12 d ago |
| Cross-site request forgery (CSRF) CVE-2026-92799 | Medium 5.3 | Up to 28.2 | Fixed in a later version (latest 28.4) | 12 d ago |
| Broken access control CVE-2026-91847 | Medium 4.8 | Before 28.2 | Fixed in 28.2 | 19 Sep 2026 |
| Broken access control CVE-2026-89063 | High 7.5 | Up to 28.1 | Fixed in a later version (latest 28.4) | 16 Sep 2026 |
| Broken access control CVE-2026-2520 | Medium 5.4 | Up to 27.2 | Fixed in a later version (latest 28.4) | 8 Sep 2026 |
| Cross-site scripting (XSS) CVE-2026-13424 | High 7.2 | Up to 27.7 | Fixed in a later version (latest 28.4) | 16 Aug 2026 |
| Broken access control CVE-2026-12905 | Medium 4.3 | Up to 27.7 | Fixed in a later version (latest 28.4) | 16 Aug 2026 |
| SQL injection CVE-2026-13395 | High 8.6 | Before 27.8 | Fixed in 27.8 | 30 Jul 2026 |
| SQL injection CVE-2026-14516 | High 7.5 | Up to 27.5 | Fixed in a later version (latest 28.4) | 28 Jul 2026 |
| Cross-site scripting (XSS) CVE-2026-5513 | High 7.2 | Up to 27.2 | Fixed in a later version (latest 28.4) | 13 Jun 2026 |
| Security weakness CVE-2026-2519 | Medium 5.3 | Up to 27.0 | Fixed in a later version (latest 28.4) | 9 Apr 2026 |
| Cross-site scripting (XSS) CVE-2024-5584 | Medium 6.4 | Up to 23.2 | Fixed in a later version (latest 28.4) | 11 Jun 2024 |
| Cross-site scripting (XSS) CVE-2018-6891 | Medium 6.1 | Before 14.5 | Fixed in 14.5 | 11 Feb 2018 |
Read the published descriptions
- CVE-2026-86841, 27 Sep 2026
- The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged maintenance feature to administrators, allowing users granted a custom booking-management capability, which an administrator must explicitly assign, to inject arbitrary PHP objects, overwrite privileged site options, and read stored integration secrets. CVE record
- CVE-2026-86839, 27 Sep 2026
- The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff members' appointments and payments, including the associated customer's personal information. CVE record
- CVE-2026-93399, 25 Sep 2026
- The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX actions. This is due to the 'bookly_get_form_id' handler blindly storing the attacker-controlled 'order_id' from the submitted form_data into a new booking session, which the 'bookly_render_complete' handler then trusts to look up and return the corresponding Order's secret token without verifying that the current session created that order. This makes it possible for unauthenticated attackers to enumerate sequential order IDs, disclose other customers' order tokens, retrieve calendar/appointment information via 'bookly_add_to_calendar' and permanently delete arbitrary non-completed bookings via 'bookly_rollback_order', which cascade-deletes the customer_appointment and (when no other customers are attached) the underlying appointment. CVE record
- CVE-2026-92799, 25 Sep 2026
- The Online Scheduling and Appointment Booking System - Bookly plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in all versions up to, and including, 28.2. This is due to the `postValidateCustomer()` function using a loose PHP inequality operator (`!=`) to compare the session-stored one-time verification code against the attacker-supplied `verification_code` parameter - a flaw that is further exposed by the booking AJAX controller registering all its methods as `wp_ajax_nopriv_` handlers and unconditionally overriding `csrfTokenValid()` to return true, leaving the endpoint both unauthenticated and CSRF-unprotected. This makes it possible for unauthenticated attackers to bypass the phone/email ownership verification step and overwrite the name, email, phone, and address fields of any arbitrary existing Bookly customer record, redirecting that customer's booking notifications to attacker-controlled contact details. The bypass is achievable because the `json_data` input channel decodes input via `json_decode()`, which preserves real PHP types and causes the `wp_kses` filter to leave non-string values such as the JSON boolean `true` untouched; submitting `true` as the `verification_code` satisfies the loose comparison against the session's non-zero integer code (generated by `mt_rand(100000, 999999)`), causing `true != <non-zero int>` to evaluate as `false` and the guard to be bypassed. CVE record
- CVE-2026-91847, 19 Sep 2026
- The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversation actions, allowing any unauthenticated visitor to read another visitor's assistant messages and to inject messages into their in-progress conversation. CVE record
- CVE-2026-89063, 16 Sep 2026
- The Online Scheduling and Appointment Booking System - Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.1 via the 'conversation_id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to read the full AI booking conversation transcript of any customer - leaking names, email addresses, phone numbers, and appointment details echoed by the assistant - and inject arbitrary messages into any victim conversation that are subsequently replayed to the Cloud AI worker along with the full private history. Because AI conversations are stored with no owner, user, or session identifier and conversation IDs are sequential integers, an unauthenticated attacker can enumerate all customer conversations simply by incrementing the conversation_id parameter. CVE record
- CVE-2026-2520, 8 Sep 2026
- The Online Scheduling and Appointment Booking System - Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'updateAddon' function in all versions up to, and including, 27.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update any plugin with a main file of 'main.php' to its latest version. CVE record
- CVE-2026-13424, 16 Aug 2026
- The Online Scheduling and Appointment Booking System - Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action in all versions up to, and including, 27.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injection point is the bookly_speed_up_update_addons AJAX action, which is registered as wp_ajax_nopriv_* and therefore reachable without authentication; the payload is stored verbatim in the bookly_log.details column when a request is submitted without a valid signature, and executes when an administrator later views the Diagnostics → Logs page. CVE record
- CVE-2026-12905, 16 Aug 2026
- The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via the appointment() method of the Mobile Staff Cabinet API (resource=appointment, action=bookly_mobile_staff_cabinet) in frontend/modules/mobile_staff_cabinet/api/handlers/Handler1_0.php. This is due to the handler loading an Appointment by the attacker-supplied params[id] without verifying that the appointment's staff_id matches the authenticated staff member, whereas sibling operations (deleteAppointment, saveAppointment, appointments list) correctly scope to $this->staff->getId() when $this->role === ROLE_STAFF. This makes it possible for authenticated attackers, with staff-level mobile cabinet access (any valid access_key token bound to a Staff entity), to read appointment details - including the internal note and the full customer_appointments collection (customer full_name, email, phone, notes, custom_fields, extras, payment_total, payment_type, payment_status) - belonging to other staff members by enumerating sequential appointment IDs. CVE record
- CVE-2026-13395, 30 Jul 2026
- The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data such as password hashes from the database. CVE record
- CVE-2026-14516, 28 Jul 2026
- The Online Scheduling and Appointment Booking System - Bookly plugin for WordPress is vulnerable to time-based SQL Injection via the 'staff_ids' parameter in all versions up to, and including, 27.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires a two-request chain: an attacker first calls the unauthenticated bookly_get_form_id action to seed a booking session carrying malicious staff_ids values, then triggers bookly_render_time to cause the tainted array to reach the vulnerable query; CSRF/nonce validation is absent on both endpoints, meaning this chain can be initiated cross-site. CVE record
- CVE-2026-5513, 13 Jun 2026
- The Online Scheduling and Appointment Booking System - Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-customer-full-name' cookie in versions up to, and including, 27.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires 'Remember personal information in cookies' setting to be enabled (disabled by default). CVE record
- CVE-2026-2519, 9 Apr 2026
- The Online Scheduling and Appointment Booking System - Bookly plugin for WordPress is vulnerable to price manipulation via the 'tips' parameter in all versions up to, and including, 27.0. This is due to the plugin trusting a user-supplied input without server-side validation against the configured price. This makes it possible for unauthenticated attackers to submit a negative number to the 'tips' parameter, causing the total price to be reduced to zero. CVE record
- CVE-2024-5584, 11 Jun 2024
- The WordPress Online Booking and Scheduling Plugin - Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Color Profile parameter in all versions up to, and including, 23.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with the staff member role and Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2018-6891, 11 Feb 2018
- Bookly #1 WordPress Booking Plugin Lite before 14.5 has XSS via a jQuery.ajax request to ng-payment_details_dialog.js. CVE record
What to do if you run Online Scheduling and Appointment Booking System
If you run Online Scheduling and Appointment Booking System, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Online Scheduling and Appointment Booking System vulnerabilities
Free. We email you when a new vulnerability is published for Online Scheduling and Appointment Booking System, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.