Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-86839 1 Wordpress-extensions 1 Bookly 2026-09-27 N/A
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff members' appointments and payments, including the associated customer's personal information.
CVE-2026-86841 1 Wordpress-extensions 1 Bookly 2026-09-27 N/A
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged maintenance feature to administrators, allowing users granted a custom booking-management capability, which an administrator must explicitly assign, to inject arbitrary PHP objects, overwrite privileged site options, and read stored integration secrets.