Product
The Bookly WordPress plugin up to version 28.2 contains multiple IDOR vulnerabilities in AJAX handlers allowing unauthenticated attackers to access customer data and delete arbitrary appointments.