DIRAS TAKE
Urgent: public exploit code exists and the flaw requires no authentication, so expose-restricted Bookly installations should be mitigated immediately and patched when an update is released.
What is CVE-2026-93399?
Unauthenticated attackers can access and manipulate other customers' bookings in the Bookly Online Scheduling and Appointment Booking System; this is tracked as CVE-2026-93399. Versions up to and including 28.2 on the 28.x branch are affected. An attacker only needs network access to the affected WordPress site (no login or user interaction) to call vulnerable AJAX actions and enumerate sequential order IDs to obtain order tokens, read calendar/appointment data, or delete non-completed bookings. The weakness is classified as CWE-639 (Authorization Bypass Through User-Controlled Key).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Which versions of ladela Online Scheduling and Appointment Booking System – Bookly are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 28.x | 28.2 and earlier |
Is CVE-2026-93399 being exploited?
Public exploit code is available.
How to fix CVE-2026-93399
- Remove or restrict access to the vulnerable Bookly AJAX endpoints (block bookly_get_form_id, bookly_render_complete, bookly_add_to_calendar, bookly_rollback_order) at the web application or WAF level.
- Restrict exposure by limiting access to the WordPress site to trusted networks or IPs where feasible.
- Monitor web and application logs for calls to the listed AJAX actions and for suspicious order_id enumeration patterns.
- Apply the vendor's official guidance and install vendor patches as soon as they are released.
Frequently asked questions
Is CVE-2026-93399 being actively exploited?
Public exploit code is available for CVE-2026-93399.
Which Bookly versions are affected by CVE-2026-93399?
Bookly versions on the 28.x branch up to and including 28.2 are affected by CVE-2026-93399.
Is there a patch for CVE-2026-93399?
There is no fixed version listed for Bookly in the provided facts; follow the vendor guidance and apply any future updates when they are released.
Does CVE-2026-93399 require authentication?
No, CVE-2026-93399 in Bookly can be exploited without authentication via publicly reachable AJAX actions.
References
- nvd.nist.gov/vuln/detail/CVE-2026-93399
- cve.org/CVERecord?id=CVE-2026-93399
- wordfence.com/threat-intel/vulnerabilities/id/d45a01e5-0e69-4d95-b609-b9002b3776da?source=cve
- plugins.trac.wordpress.org/browser/bookly-responsive-appointment-booking-tool/tags/28.2/frontend/modules/booking/Ajax.php#L733
- plugins.trac.wordpress.org/browser/bookly-responsive-appointment-booking-tool/tags/28.2/frontend/modules/booking/Ajax.php#L46
- plugins.trac.wordpress.org/browser/bookly-responsive-appointment-booking-tool/tags/28.2/frontend/modules/booking/Ajax.php#L1111
- plugins.trac.wordpress.org/browser/bookly-responsive-appointment-booking-tool/tags/28.2/frontend/modules/payment/Ajax.php#L74
- plugins.trac.wordpress.org/browser/bookly-responsive-appointment-booking-tool/tags/28.2/lib/base/Gateway.php#L301
- plugins.trac.wordpress.org/browser/bookly-responsive-appointment-booking-tool/tags/28.2/lib/UserBookingData.php#L360
- plugins.trac.wordpress.org/changeset?reponame=&old=3707284%40bookly-responsive-appointment-booking-tool&new=3707284%40bookly-responsive-appointment-booking-tool
- All ladela CVEs on CVE Radar
- CVEs published in September 2026