CVE-2026-89063: CWE-639 Authorization Bypass Through User-Controlled Key in ladela Online Scheduling and Appointment Booking System – Bookly
The Bookly plugin for WordPress, used for online scheduling and appointment booking, has an authorization bypass vulnerability (CWE-639) in all versions up to 28.1. This flaw allows unauthenticated attackers to access and enumerate AI booking conversation transcripts of any customer by manipulating the 'conversation_id' parameter. Sensitive customer data such as names, emails, phone numbers, and appointment details can be leaked. Attackers can also inject arbitrary messages into victim conversations, which are replayed to the AI system. The vulnerability arises because conversation IDs are sequential integers and conversations lack ownership or session identifiers.
AI Analysis
Technical Summary
CVE-2026-89063 describes an Insecure Direct Object Reference vulnerability in the Bookly WordPress plugin (versions up to 28.1). The 'conversation_id' parameter is user-controlled and lacks proper validation, enabling unauthenticated attackers to enumerate and access all AI booking conversation transcripts. This leads to unauthorized disclosure of personal information and allows injection of arbitrary messages into conversations. The root cause is missing authorization checks combined with sequential conversation IDs and absence of ownership metadata in stored conversations.
Potential Impact
An unauthenticated attacker can read private AI booking conversation transcripts containing sensitive customer information such as names, email addresses, phone numbers, and appointment details. The attacker can also inject arbitrary messages into any victim conversation, potentially influencing the AI assistant's behavior. This results in a high confidentiality impact but does not affect integrity or availability according to the CVSS vector.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the plugin and monitor for suspicious activity. Avoid exposing the 'conversation_id' parameter to unauthenticated users. Implement additional access controls or disable the affected feature if possible.
CVE-2026-89063: CWE-639 Authorization Bypass Through User-Controlled Key in ladela Online Scheduling and Appointment Booking System – Bookly
Description
The Bookly plugin for WordPress, used for online scheduling and appointment booking, has an authorization bypass vulnerability (CWE-639) in all versions up to 28.1. This flaw allows unauthenticated attackers to access and enumerate AI booking conversation transcripts of any customer by manipulating the 'conversation_id' parameter. Sensitive customer data such as names, emails, phone numbers, and appointment details can be leaked. Attackers can also inject arbitrary messages into victim conversations, which are replayed to the AI system. The vulnerability arises because conversation IDs are sequential integers and conversations lack ownership or session identifiers.
CVSS v3.1
Score 7.5high
Affected software
ladela
Online Scheduling and Appointment Booking System – Bookly
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-89063 describes an Insecure Direct Object Reference vulnerability in the Bookly WordPress plugin (versions up to 28.1). The 'conversation_id' parameter is user-controlled and lacks proper validation, enabling unauthenticated attackers to enumerate and access all AI booking conversation transcripts. This leads to unauthorized disclosure of personal information and allows injection of arbitrary messages into conversations. The root cause is missing authorization checks combined with sequential conversation IDs and absence of ownership metadata in stored conversations.
Potential Impact
An unauthenticated attacker can read private AI booking conversation transcripts containing sensitive customer information such as names, email addresses, phone numbers, and appointment details. The attacker can also inject arbitrary messages into any victim conversation, potentially influencing the AI assistant's behavior. This results in a high confidentiality impact but does not affect integrity or availability according to the CVSS vector.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the plugin and monitor for suspicious activity. Avoid exposing the 'conversation_id' parameter to unauthenticated users. Implement additional access controls or disable the affected feature if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-09-10T18:38:58.201Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aaa1f5555bf5e2cf50301bc
Added to database: 09/16/2026, 04:47:17 UTC
Last enriched: 09/16/2026, 05:01:32 UTC
Last updated: 09/16/2026, 05:21:24 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.