Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a critical vulnerability in the Bookly WordPress plugin that could allow unauthenticated attackers to access sensitive customer information and delete bookings. The issue stems from how the plugin handles order data, potentially exposing customer details and appointment records.
- Attackers can access customer data and delete bookings.
- This impacts customer trust and data privacy.
- Confirm relevance and verify exposure of the booking system.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can target the Bookly WordPress plugin by sending specially crafted AJAX requests. The plugin's handling of these requests allows an attacker to manipulate order IDs, potentially leading to the disclosure of sensitive customer booking information or the deletion of appointments.
- No authentication required.
- Manipulate AJAX actions to access data.
- Disclose data or delete bookings.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, unauthenticated attackers could potentially access and manipulate booking information. This could involve enumerating order IDs, disclosing other customers' order tokens, retrieving calendar and appointment details, and deleting non-completed bookings.
- Customer order tokens could be exposed.
- Attackers could guess sequential order IDs.
- Arbitrary bookings may be deleted.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Bookly plugin for WordPress is susceptible to critical vulnerabilities due to insecure handling of AJAX requests. WordPress administrators and site reliability engineers should prioritize identifying all instances of the Bookly plugin across their WordPress deployments. Subsequently, they must assess the exposure of these instances, specifically determining if they are publicly accessible and processing sensitive customer data. Once confirmed, engagement with the accountable application owner or vendor management team is necessary to plan and execute remediation, which may involve plugin updates or temporary risk mitigation strategies.
- Application owners, platform teams.
- Verify public exposure and data criticality.
- Plan updates or implement temporary controls.