Known Vulnerabilities for Bookly by Booking-wp-plugin
Listed below are 6 of the newest known vulnerabilities associated with "Bookly" by "Booking-wp-plugin".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-96348 json | Unauthenticated Broken Access Control in Bookly <= 28.2 versions. | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-96347 json | Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions. | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-93399 json | The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via ... | Not Provided | 2026-09-25 | 2026-09-26 |
| CVE-2026-92799 json | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Authorization Bypass vi... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-89063 json | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object ... | Not Provided | 2026-09-16 | 2026-09-17 |
| CVE-2026-86838 json | The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before comput... | Not Provided | 2026-09-28 | 2026-09-28 |
| CVE-2026-86837 json | The Bookly WordPress plugin before 28.3 does not properly verify a customer's identity before updating their stored details, ... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-61949 json | Unauthenticated SQL Injection in Bookly <= 27.7 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-61944 json | Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-14516 json | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injectio... | Not Provided | 2026-07-28 | 2026-07-28 |