{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/bookly--28.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:bookly:bookly:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-93399"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Bookly (\u003c= 28.2)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Bookly"],"content_html":"\u003cp\u003eThe Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference (IDOR) exploitation in versions 28.2 and earlier. The vulnerability stems from improper validation within several AJAX handlers, specifically 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar', and 'bookly_rollback_order'.\u003c/p\u003e\n\u003cp\u003eThe 'bookly_get_form_id' handler accepts an attacker-supplied 'order_id' from user-submitted form data and stores it in the booking session without verification. Subsequent handlers, such as 'bookly_render_complete', trust this session-stored ID to look up and return sensitive order tokens. This flaw enables unauthenticated attackers to enumerate sequential order IDs, leading to the unauthorized disclosure of customer order tokens and appointment details. Furthermore, the 'bookly_rollback_order' handler allows attackers to permanently delete arbitrary non-completed bookings, which triggers cascading deletions of associated customer appointment records. This vulnerability poses a significant risk to data privacy and service integrity for organizations utilizing the Bookly plugin.\u003c/p\u003e\n","date_modified":"2026-09-25T10:52:00Z","date_published":"2026-09-25T10:52:00Z","id":"https://feed.craftedsignal.io/briefs/2026-09-bookly-idor/","summary":"The Bookly WordPress plugin up to version 28.2 contains multiple IDOR vulnerabilities in AJAX handlers allowing unauthenticated attackers to access customer data and delete arbitrary appointments.","title":"CVE-2026-93399 - IDOR Vulnerability in Bookly WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-bookly-idor/"}],"language":"en","title":"CraftedSignal Threat Feed - Bookly (\u003c= 28.2)","version":"https://jsonfeed.org/version/1.1"}