What is CVE-2026-12905?
This is an Insecure Direct Object Reference vulnerability in the Bookly WordPress plugin up to version 27.7, affecting the appointment() method of the Mobile Staff Cabinet API. Unauthorized users can access others' appointment data via the 'bookly_mobile_staff_cabinet' request. Immediate update to the latest plugin version is highly recommended.
Azərbaycanca: Bu, Bookly WordPress plugin-inin 27.7-dək olan versiyalarında Mobile Staff Cabinet API-nin appointment() metodunda aşkar edilmiş IDOR zəifliyidir. İcazəsiz istifadəçilər 'bookly_mobile_staff_cabinet' sorğusu vasitəsilə digərlərinin görüş məlumatlarına daxil ola bilər. Plugin'i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of the Bookly plugin are affected by CVE-2026-12905?
This IDOR vulnerability affects the Bookly WordPress plugin up to version 27.7.
How to protect against CVE-2026-12905?
Immediate update to the latest plugin version is highly recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.