External risk intelligence

Bookly Plugin Insecure Direct Object Reference Allows Data Disclosure and Deletion

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-93399

The vulnerability exists in a WordPress booking plugin that handles AJAX actions on the frontend. Such plugins are designed to be public-facing to allow customers to interact with appointment scheduling and booking forms directly from the internet.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in the Bookly WordPress plugin that could allow unauthenticated attackers to access sensitive customer information and delete bookings. The issue stems from how the plugin handles order data, potentially exposing customer details and appointment records.

  • Attackers can access customer data and delete bookings.
  • This impacts customer trust and data privacy.
  • Confirm relevance and verify exposure of the booking system.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can target the Bookly WordPress plugin by sending specially crafted AJAX requests. The plugin's handling of these requests allows an attacker to manipulate order IDs, potentially leading to the disclosure of sensitive customer booking information or the deletion of appointments.

  • No authentication required.
  • Manipulate AJAX actions to access data.
  • Disclose data or delete bookings.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, unauthenticated attackers could potentially access and manipulate booking information. This could involve enumerating order IDs, disclosing other customers' order tokens, retrieving calendar and appointment details, and deleting non-completed bookings.

  • Customer order tokens could be exposed.
  • Attackers could guess sequential order IDs.
  • Arbitrary bookings may be deleted.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Bookly plugin for WordPress is susceptible to critical vulnerabilities due to insecure handling of AJAX requests. WordPress administrators and site reliability engineers should prioritize identifying all instances of the Bookly plugin across their WordPress deployments. Subsequently, they must assess the exposure of these instances, specifically determining if they are publicly accessible and processing sensitive customer data. Once confirmed, engagement with the accountable application owner or vendor management team is necessary to plan and execute remediation, which may involve plugin updates or temporary risk mitigation strategies.

  • Application owners, platform teams.
  • Verify public exposure and data criticality.
  • Plan updates or implement temporary controls.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Bookly plugin for WordPress?

Bookly is a popular plugin for WordPress sites that automates appointment scheduling. It provides the necessary frontend tools for businesses to display calendars, manage customer bookings, and process payments directly through their website.

What does Insecure Direct Object Reference (IDOR) mean for CVE-2026-93399?

CWE-639, or IDOR, happens when an application gives users direct access to objects like database records without verifying they are authorized to see them. In this case, the plugin trusts user-supplied order IDs without checking if the requester owns that specific booking session.

How do attackers trigger this vulnerability?

Attackers trigger this by sending specific AJAX requests to the site. They do not need to log in or hold an account. By submitting manipulated order IDs in the request, they can trick the system into revealing private data or deleting records. Simply visiting the site normally does not trigger the bug.

Is my site at risk if I use Bookly?

If you run the affected version of Bookly, your site is at risk. Halo Surface Signal notes this is highly likely because Bookly is a frontend-facing plugin, meaning it is intentionally exposed to the internet to allow customer interaction, which provides a direct path for attackers.

What steps should I take to respond to CVE-2026-93399?

Start by auditing your WordPress environment to identify all active installations of the Bookly plugin. Confirm if these instances are publicly accessible and handling sensitive customer data. Once identified, contact your application owners to plan for plugin updates or evaluate temporary mitigation measures.

References