CVE-2026-104898

CVE-2026-104898 published: The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.4 via the 'id, wp_user_id' parameter due to missing validation on a user controlled...

View full NVD advisory → ← Back to CVE watch