Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-92799— Online Scheduling and Appointment Booking System <= 28.2 - Unauthenticated Authorization Bypass via PHP Type Juggling via 'verification_code' Parameter Type Juggling via json_data

Quick assessment

Affected
ladela Online Scheduling and Appointment Booking System – Bookly
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 插件 “Online Scheduling and Appointment Booking System – Bookly” 存在授权绕过漏洞(通过 PHP 类型比较),影响所有 28.2 及以下版本。该漏洞源于 函数使用松散的不等运算符( )将存储在会话中的单次验证码与攻击者提供的 参数进行比较。此外,预订 AJAX 控制器将所有方法注册为 处理程序,并无条件地将 覆盖为返回 ,导致该端点既无需认证,也缺乏 CSRF 保护。 这使得未认证的攻击者能够绕过电话/邮箱所有权验证步骤,并覆盖任意现有

CVSS 5.3 · Medium EPSS 0.32% · P22
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92799

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Online Scheduling and Appointment Booking System <= 28.2 - Unauthenticated Authorization Bypass via PHP Type Juggling via 'verification_code' Parameter Type Juggling via json_data
Source: CVE Program / CVE List V5
Vulnerability Description
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in all versions up to, and including, 28.2. This is due to the `postValidateCustomer()` function using a loose PHP inequality operator (`!=`) to compare the session-stored one-time verification code against the attacker-supplied `verification_code` parameter — a flaw that is further exposed by the booking AJAX controller registering all its methods as `wp_ajax_nopriv_` handlers and unconditionally overriding `csrfTokenValid()` to return true, leaving the endpoint both unauthenticated and CSRF-unprotected. This makes it possible for unauthenticated attackers to bypass the phone/email ownership verification step and overwrite the name, email, phone, and address fields of any arbitrary existing Bookly customer record, redirecting that customer's booking notifications to attacker-controlled contact details. The bypass is achievable because the `json_data` input channel decodes input via `json_decode()`, which preserves real PHP types and causes the `wp_kses` filter to leave non-string values such as the JSON boolean `true` untouched; submitting `true` as the `verification_code` satisfies the loose comparison against the session's non-zero integer code (generated by `mt_rand(100000, 999999)`), causing `true != <non-zero int>` to evaluate as `false` and the guard to be bypassed.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ladela Online Scheduling and Appointment Booking System – Bookly 0 ~ 28.2 -

II. Public POCs for CVE-2026-92799

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92799

请登录查看更多情报信息。

Security Blog Posts for CVE-2026-92799 (1)

Other References for CVE-2026-92799 (8)

IV. Related Vulnerabilities

V. Comments for CVE-2026-92799

No comments yet


Leave a comment