Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-103365— Online Scheduling and Appointment Booking System <= 28.4 - Unauthenticated Sensitive Information Exposure in 'phone' Parameter to bookly_render_details

Quick assessment

Affected
ladela Online Scheduling and Appointment Booking System – Bookly
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 插件 Bookly – Online Scheduling and Appointment Booking System 在 28.4 及更早版本中存在敏感信息泄露漏洞,该漏洞可通过经典预订表单的“详细信息”步骤触发。 端点同时注册了 和 ,意味着无需身份验证即可访问。此外,该模块重写了 方法,使其始终返回 true,从而绕过 CSRF 保护。在 方法中,代码直接调用 来加载持久化的客户实体,且仅依赖攻击者提供的电话号码(或电子邮件)作为键进行查找,未调用插件自带的 谓词进行身份确认。 当站点所

CVSS 5.3 · Medium

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-103365

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Online Scheduling and Appointment Booking System <= 28.4 - Unauthenticated Sensitive Information Exposure in 'phone' Parameter to bookly_render_details
Source: CVE Program / CVE List V5
Vulnerability Description
The Bookly – Online Scheduling and Appointment Booking System plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 28.4 via the classic booking form's Details step. The endpoint bookly_render_details is registered for both wp_ajax and wp_ajax_nopriv, the module overrides csrfTokenValid() to always return true, and Bookly\Frontend\Components\Booking\InfoText::getCodes() calls UserBookingData::getCustomer() to load the persisted Customer entity keyed solely by the attacker-supplied phone (or email) with no invocation of the plugin's own customerIdentityConfirmed() predicate. When a site owner has placed the supported {client_name}, {client_email}, {client_phone}, or {client_note} placeholders into the Details step's Appearance information text, the matched customer's stored name, email, phone and internal notes are substituted into the returned HTML. This makes it possible for unauthenticated attackers who know only a registered customer's primary phone (or email) to read that customer's stored personal data.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ladela Online Scheduling and Appointment Booking System – Bookly 0 ~ 28.4 -

II. Public POCs for CVE-2026-103365

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-103365

请登录查看更多情报信息。

Other References for CVE-2026-103365 (8)

Same Patch Batch · ladela · 2026-10-10 · 3 CVEs total

CVE-2026-12626 7.2 HIGH Online Scheduling and Appointment Booking System <= 28.2 - Authenticated (Custom+) PHP Obj
CVE-2026-104898 6.8 MEDIUM Online Scheduling and Appointment Booking System <= 28.4 - Insecure Direct Object Referenc

IV. Related Vulnerabilities

V. Comments for CVE-2026-103365

No comments yet


Leave a comment