Junglewise Threat Intelligence

CVE-2026-42667: Bookly WordPress plugin sensitive data exposure

CVE-2026-42667 · Severity: high · CVSS 7.5 · Published 2026-06-15

Technologies: Bookly. Vendors: Bookly.

Executive brief

The Bookly plugin for WordPress, which is used for managing online appointments and bookings, contains a security flaw that allows unauthorized individuals to access sensitive information. An attacker could exploit this to view data that should be private, potentially leading to further attacks or the exposure of customer details. This issue affects all versions of the plugin up to and including 27.4.

Technical details

A sensitive data exposure vulnerability (CWE-201) exists in the Bookly plugin for WordPress through version 27.4. The flaw allows an unauthenticated remote attacker to access sensitive information that is normally restricted to authorized users. This occurs because the application improperly includes sensitive data in responses sent to unauthenticated users. An attacker can exploit this over the network without any user interaction. The vulnerability is resolved in version 27.5.

Affected products

  • Bookly Bookly <= 27.4

Timeline

  • 2026-04-10: other: Reported by Tiago Ventura (@perses)
  • 2026-05-10: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date

References

Related threats