Executive brief
Bookify, a WordPress plugin used for booking and scheduling, contains a security flaw that allows users with basic 'Subscriber' accounts to access information they should not be able to see. This could lead to the unauthorized exposure of sensitive data managed by the plugin. Business operations may be impacted if customer or booking information is leaked, potentially leading to privacy compliance issues.
Technical details
The Bookify plugin for WordPress (versions 1.1.1 and below) suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). An attacker authenticated with low-level 'Subscriber' privileges can exploit this flaw over the network without any user interaction. The vulnerability allows for unauthorized data retrieval (Confidentiality: High), though it does not appear to allow for data modification or service disruption based on the CVSS vector. The issue is resolved in version 1.1.2.
Affected products
- myCred Bookify <= 1.1.1
Timeline
- 2025-11-29: other: Reported by researcher benzdeus
- 2026-04-23: advisory: Initial disclosure by Patchstack
- 2026-06-15: disclosed: NVD publication date
- 2026-04-23: patched: Version 1.1.2 released