WordPress 在线排班与预约预订系统插件 Bookly 存在不安全的直接对象引用(Insecure Direct Object Reference)漏洞,影响所有 28.4 及更低版本。该漏洞源于对 'id' 和 'wp_user_id' 参数缺乏对用户可控键值的有效验证,使得拥有订阅者(subscriber)及以上权限的已认证攻击者能够覆盖任何 Bookly 员工记录所绑定的 WordPress 账户关联关系,包括管理员拥有的记录。此操作可实质性地劫持更高权限员工账户的关联关系,从而实现权限提升。 利用此漏
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ladela | Online Scheduling and Appointment Booking System – Bookly | 0 ~ 28.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12626 | 7.2 HIGH | Online Scheduling and Appointment Booking System <= 28.2 - Authenticated (Custom+) PHP Obj |
| CVE-2026-103365 | 5.3 MEDIUM | Online Scheduling and Appointment Booking System <= 28.4 - Unauthenticated Sensitive Infor |
No comments yet