WordPress 插件 Bookly – Online Scheduling and Appointment Booking System 在 28.4 及更早版本中存在敏感信息泄露漏洞,该漏洞可通过经典预订表单的“详细信息”步骤触发。 端点同时注册了 和 ,意味着无需身份验证即可访问。此外,该模块重写了 方法,使其始终返回 true,从而绕过 CSRF 保护。在 方法中,代码直接调用 来加载持久化的客户实体,且仅依赖攻击者提供的电话号码(或电子邮件)作为键进行查找,未调用插件自带的 谓词进行身份确认。 当站点所
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ladela | Online Scheduling and Appointment Booking System – Bookly | 0 ~ 28.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12626 | 7.2 HIGH | Online Scheduling and Appointment Booking System <= 28.2 - Authenticated (Custom+) PHP Obj |
| CVE-2026-104898 | 6.8 MEDIUM | Online Scheduling and Appointment Booking System <= 28.4 - Insecure Direct Object Referenc |
No comments yet