CVE-CVE-2026-93399
Severity
CRITICAL
CVSS Score
9.1
Description
The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX actions. This is due to the 'bookly_get_form_id' handler blindly storing the attacker-controlled 'order_id' from the submitted form_data into a new booking session, which the 'bookly_render_complete' handler then trusts to look up and return the corresponding Order...
PoCs for CVE-CVE-2026-93399
CVE-2026-93399
Buffer Overflow
Python
0
murrez
2026-09-25