Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns an unauthenticated SQL injection vulnerability in the Bookly plugin, a tool used for appointment booking. The issue allows for unauthorized access and manipulation of data within the affected system due to its network-exploitable nature. The primary concern at this stage is to confirm if this specific technology is in use and, if so, to assess the exposure.
- Unauthenticated data access in booking software.
- Confirms relevance and exposure is the main concern.
- Verify use and assess potential data risk.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by sending specially crafted requests to a vulnerable Bookly installation. Because the vulnerability is unauthenticated, no login is required. The attacker could target the SQL database, potentially leading to unauthorized access to sensitive information or disruption of services.
- No authentication required.
- Unauthenticated SQL injection.
- Data exposure and service disruption.
Live Threat
Current exploitation, exposure, and threat context
This unauthenticated SQL injection vulnerability in Bookly could allow an attacker to execute arbitrary SQL commands, potentially impacting the confidentiality and integrity of the booking system's data. The vulnerability exists in versions up to and including 27.7.
- Booking system data could be affected.
- Network access could lead to exposure.
- Unauthorized data access or modification may occur.
Operational Fix
Recommended remediation, mitigation, and detection steps
SQL Injection in Bookly affects unauthenticated users and requires immediate attention from teams managing WordPress applications. The first step is to locate all Bookly instances, confirm their reachability and business criticality, and then assign ownership for remediation.
- Application owners should prioritize this.
- Verify Bookly installation reachability.
- Plan risk-based remediation.