WordPress Online Booking and Scheduling Plugin – Bookly, CVE-2026-91847
- CVE, Research URL
- Published on
- Sep 19, 2026
- Research Description
- The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversation actions, allowing any unauthenticated visitor to read another visitor's assistant messages and to inject messages into their in-progress conversation.
- Affected versions
-
max 28.2.
- Status
-
vulnerable