Vendor
IDOR Vulnerability in Bookly WordPress Plugin
2 TTPs 1 CVEAn Insecure Direct Object Reference (IDOR) vulnerability in the Bookly WordPress plugin allows unauthenticated attackers to enumerate and exfiltrate private AI booking transcripts via sequential ID incrementation.
Stored XSS Vulnerability in Bookly WordPress Plugin
1 rule 2 TTPs 1 CVEThe Bookly WordPress plugin contains a stored XSS vulnerability via the bookly_speed_up_update_addons AJAX action, allowing unauthenticated attackers to inject malicious scripts that execute in an administrator's browser.
CVE-2026-14516 - Bookly WordPress Plugin Time-Based SQL Injection
1 rule 2 TTPs 1 CVEUnauthenticated attackers can exploit a time-based SQL Injection vulnerability (CVE-2026-14516) in the Bookly WordPress plugin, affecting versions up to and including 27.5, via the 'staff_ids' parameter, chaining requests to `bookly_get_form_id` and `bookly_render_time` to extract sensitive database information due to insufficient input escaping and lack of CSRF protection.