{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-89063/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:bookly:bookly:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-89063"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Bookly (\u003c= 28.1)"],"_cs_severities":["high"],"_cs_tags":["web-application","wordpress","idor","cve-2026-89063"],"_cs_type":"advisory","_cs_vendors":["Bookly"],"content_html":"\u003cp\u003eThe Bookly WordPress plugin, specifically versions 28.1 and earlier, contains an Insecure Direct Object Reference (IDOR) vulnerability identified as CVE-2026-89063. The vulnerability stems from the 'conversation_id' parameter in the plugin's AI booking functionality, which fails to enforce access control or validate that the requesting user owns the requested conversation session. Because the conversation IDs are assigned as sequential integers, an unauthenticated attacker can systematically enumerate these values to access sensitive customer data stored in AI booking transcripts, including names, email addresses, phone numbers, and appointment details. Beyond data exfiltration, the flaw permits attackers to inject arbitrary messages into active or historical conversations, which are then processed by the cloud AI worker. This capability creates a significant risk for unauthorized access to customer interactions and data leakage across any WordPress site running the affected plugin versions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated actors to harvest PII for all scheduled appointments and manipulate interactions with the AI assistant. This presents a severe privacy risk to organizations using the plugin for scheduling, potentially leading to unauthorized data exposure and the compromise of automated customer service workflows.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and IT teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Bookly plugin for WordPress to the latest available version beyond 28.1 to mitigate CVE-2026-89063.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for anomalous, high-frequency GET or POST requests directed at the Bookly conversation API endpoint involving incrementing integer parameters in the 'conversation_id' field.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized access patterns where a single IP address requests a broad range of sequential conversation IDs, which is a strong indicator of enumeration attempts against this IDOR vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T05:46:46Z","date_published":"2026-09-16T05:46:46Z","id":"https://feed.craftedsignal.io/briefs/2026-09-bookly-idor/","summary":"An Insecure Direct Object Reference (IDOR) vulnerability in the Bookly WordPress plugin allows unauthenticated attackers to enumerate and exfiltrate private AI booking transcripts via sequential ID incrementation.","title":"IDOR Vulnerability in Bookly WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-bookly-idor/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-89063","version":"https://jsonfeed.org/version/1.1"}