Executive brief
Bookly is a WordPress plugin that manages appointment booking and scheduling. An unauthenticated attacker can read another visitor's AI assistant conversation messages and inject their own messages into an active conversation due to missing ownership verification. This allows exposure of customer scheduling details and conversation data without authentication.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in unauthenticated conversation actions where the plugin fails to verify that the requester owns the AI booking-assistant conversation ID. Attackers can access conversation endpoints with arbitrary conversation identifiers to read and write messages without authentication. This is a broken access control flaw allowing complete compromise of conversation confidentiality and integrity.
Affected products
- Bookly Bookly before 28.2
Timeline
- 2026-09-19: disclosed
- 2026-09-19: patched: Fixed in version 28.2