CVE-2026-86837 PUBLISHED

Bookly < 28.3 - Unauthenticated Customer PII Update via Verification Bypass

Assigner: WPScan
Reserved: 08.09.2026 Published: 25.09.2026 Updated: 25.09.2026

The Bookly WordPress plugin before 28.3 does not properly verify a customer's identity before updating their stored details, allowing unauthenticated attackers who know a customer's primary identifier to overwrite that customer's stored personal information such as name, email and address.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 5.3

Product Status

Vendor Unknown
Product Bookly
Versions Default: unaffected
  • affected from 0 to 28.3 (excl.)

Credits

  • Artus KG finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE