PatchSiren cyber security CVE debrief
CVE-2026-103365 ladela CVE debrief
CVE-2026-103365: The Online Scheduling and Appointment Booking System plugin for WordPress, versions up to and including 28.4, is vulnerable to Sensitive Information Exposure. This vulnerability allows unauthenticated attackers to access customer data, including names, emails, phones, and internal notes, via the bookly_render_details endpoint. The endpoint is registered for both wp_ajax and wp_ajax_nopriv, and the plugin overrides csrfTokenValid() to always return true. As a result, defenders responsible for WordPress installations using this plugin should assess exposure and prioritize remediation to prevent potential sensitive information exposure.
- Vendor
- ladela
- Product
- Online Scheduling and Appointment Booking System – Bookly
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for WordPress installations using the Online Scheduling and Appointment Booking System plugin should assess exposure and prioritize remediation to prevent potential sensitive information exposure. This includes verifying the exposure of affected installations, updating the plugin to a version that addresses the vulnerability, and monitoring for potential exploitation attempts.
Why it matters
CVE-2026-103365 is a sensitive information exposure vulnerability in the Online Scheduling and Appointment Booking System plugin for WordPress, allowing unauthenticated attackers to access customer data. Defenders should prioritize verifying exposure and remediation for affected installations.
- Unauthenticated attackers can access customer data, including name, email, phone, and internal notes.
- Defenders must verify exposure and remediation for affected WordPress installations.
- Remediation priority is high due to the potential for sensitive information exposure.
- Further verification is required to determine the full scope of affected versions and potential exploitation.
Technical summary
The Online Scheduling and Appointment Booking System plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 28.4. The endpoint bookly_render_details is registered for both wp_ajax and wp_ajax_nopriv, allowing unauthenticated attackers to access customer data, including names, emails, phones, and internal notes. The plugin overrides csrfTokenValid() to always return true, and BooklyFrontendComponentsBookingInfoText::getCodes() calls UserBookingData::getCustomer() to load the persisted Customer entity keyed solely by the attacker-supplied phone (or email) with no invocation of the plugin's own customerIdentityConfirmed() predicate.
Defensive priority
Defenders should prioritize verifying exposure and remediation for WordPress installations using the Online Scheduling and Appointment Booking System plugin, version 28.4 or earlier.
Recommended defensive actions
- Verify WordPress installations for the Online Scheduling and Appointment Booking System plugin, version 28.4 or earlier.
- Check for exposure by testing the 'phone' parameter in the bookly_render_details endpoint.
- Remediate by updating the plugin to a version that addresses the vulnerability, if available.
- Monitor for potential exploitation attempts.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description, affected versions, and references to code snippets. The vulnerability exists in the bookly_render_details endpoint, which is registered for both wp_ajax and wp_ajax_nopriv. The plugin's InfoText.php and Ajax.php files contain code snippets that contribute to the vulnerability. Defenders should verify the exposure of WordPress installations using the Online Scheduling and Appointment Booking System plugin, version 28.4 or earlier, and remedi
Sources and references
Verified primary and authoritative sources
-
CVE-2026-103365 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-103365
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-103365 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103365
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Online Scheduling and Appointment Booking System <= 28.4 - Unauthenticated Sensitive Information
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/103xxx/CVE-2026-103365.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/bookly-responsive-appointment-booking-tool/tags/28.3/frontend/components/booking/InfoText.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/bookly-responsive-appointment-booking-tool/tags/28.3/frontend/modules/booking/Ajax.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/bookly-responsive-appointment-booking-tool/tags/28.3/lib/UserBookingData.php
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.