cleantalk
Vulnerabilities and Security Researches

WordPress Online Booking and Scheduling Plugin – Bookly, CVE-2026-91847

CVE, Research URL

CVE-2026-91847

Published on
Sep 19, 2026
Research Description
The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversation actions, allowing any unauthenticated visitor to read another visitor's assistant messages and to inject messages into their in-progress conversation.
Affected versions
max 28.2.
Status
vulnerable