Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104898— Online Scheduling and Appointment Booking System <= 28.4 - Insecure Direct Object Reference to Authenticated (Subscriber+) Privilege Escalation via 'id' and 'wp_user_id' Parameters via Query String / JSON Body

Quick assessment

Affected
ladela Online Scheduling and Appointment Booking System – Bookly
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 在线排班与预约预订系统插件 Bookly 存在不安全的直接对象引用(Insecure Direct Object Reference)漏洞,影响所有 28.4 及更低版本。该漏洞源于对 'id' 和 'wp_user_id' 参数缺乏对用户可控键值的有效验证,使得拥有订阅者(subscriber)及以上权限的已认证攻击者能够覆盖任何 Bookly 员工记录所绑定的 WordPress 账户关联关系,包括管理员拥有的记录。此操作可实质性地劫持更高权限员工账户的关联关系,从而实现权限提升。 利用此漏

CVSS 6.8 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104898

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Online Scheduling and Appointment Booking System <= 28.4 - Insecure Direct Object Reference to Authenticated (Subscriber+) Privilege Escalation via 'id' and 'wp_user_id' Parameters via Query String / JSON Body
Source: CVE Program / CVE List V5
Vulnerability Description
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.4 via the 'id, wp_user_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the WordPress account binding of any Bookly staff record, including those owned by administrators, effectively hijacking a higher-privileged staff member's account association and escalating privileges. Exploitation requires the attacking user to be linked to at least one Bookly staff record, which occurs by default whenever an admin enables the bookly_gen_allow_staff_edit_profile option (active on fresh installs) and links a WordPress user to a staff entry.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ladela Online Scheduling and Appointment Booking System – Bookly 0 ~ 28.4 -

II. Public POCs for CVE-2026-104898

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104898

请登录查看更多情报信息。

Other References for CVE-2026-104898 (8)

Same Patch Batch · ladela · 2026-10-10 · 3 CVEs total

CVE-2026-12626 7.2 HIGH Online Scheduling and Appointment Booking System <= 28.2 - Authenticated (Custom+) PHP Obj
CVE-2026-103365 5.3 MEDIUM Online Scheduling and Appointment Booking System <= 28.4 - Unauthenticated Sensitive Infor

IV. Related Vulnerabilities

V. Comments for CVE-2026-104898

No comments yet


Leave a comment