WordPress Plugin Vulnerabilities

Bookly < 28.2 - Unauthenticated AI Assistant Conversation Disclosure and Message Injection via IDOR

Description

The plugin does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversation actions, allowing any unauthenticated visitor to read another visitor's assistant messages and to inject messages into their in-progress conversation.

Proof of Concept

Affects Plugins

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
vuxvinh
Submitter
vuxvinh
Verified
Yes

Timeline

Publicly Published
2026-09-17 (about 2 days ago)
Added
2026-09-17 (about 1 day ago)
Last Updated
2026-09-17 (about 1 day ago)

Other