Bookly WordPress plugin <= 28.1 contains an insecure direct object reference caused by missing validation on 'conversation_id' parameter, letting unauthenticated attackers read and inject messages into any AI booking conversation, exploit requires no authentication.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view