• PoC PUBLIC

CVE-2026-93399: pre-auth insecure direct object reference in ladela Online Scheduling and Appointment Booking System – Bookly

Unauthenticated attackers can access and manipulate other customers' bookings in the Bookly Online Scheduling and Appointment Booking System; this is tracked as CVE-2026-93399. Versions up to and including 28.2 on the 28.x branch are affected. An attacker only needs network access to the affected WordPress site (no login or user interaction) to call vulnerable AJAX actions and enumerate sequential order IDs to obtain order tokens, read calendar/appointment data, or delete non-completed bookings.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.1CRITICAL
EPSS
0.0037
CWE
CWE-639
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: public exploit code exists and the flaw requires no authentication, so expose-restricted Bookly installations should be mitigated immediately and patched when an update is released.

What is CVE-2026-93399?

Unauthenticated attackers can access and manipulate other customers' bookings in the Bookly Online Scheduling and Appointment Booking System; this is tracked as CVE-2026-93399. Versions up to and including 28.2 on the 28.x branch are affected. An attacker only needs network access to the affected WordPress site (no login or user interaction) to call vulnerable AJAX actions and enumerate sequential order IDs to obtain order tokens, read calendar/appointment data, or delete non-completed bookings. The weakness is classified as CWE-639 (Authorization Bypass Through User-Controlled Key).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Which versions of ladela Online Scheduling and Appointment Booking System – Bookly are affected?

BRANCHAFFECTEDFIXED
28.x28.2 and earlier

Is CVE-2026-93399 being exploited?

Public exploit code is available.

How to fix CVE-2026-93399

  1. Remove or restrict access to the vulnerable Bookly AJAX endpoints (block bookly_get_form_id, bookly_render_complete, bookly_add_to_calendar, bookly_rollback_order) at the web application or WAF level.
  2. Restrict exposure by limiting access to the WordPress site to trusted networks or IPs where feasible.
  3. Monitor web and application logs for calls to the listed AJAX actions and for suspicious order_id enumeration patterns.
  4. Apply the vendor's official guidance and install vendor patches as soon as they are released.

Frequently asked questions

Is CVE-2026-93399 being actively exploited?

Public exploit code is available for CVE-2026-93399.

Which Bookly versions are affected by CVE-2026-93399?

Bookly versions on the 28.x branch up to and including 28.2 are affected by CVE-2026-93399.

Is there a patch for CVE-2026-93399?

There is no fixed version listed for Bookly in the provided facts; follow the vendor guidance and apply any future updates when they are released.

Does CVE-2026-93399 require authentication?

No, CVE-2026-93399 in Bookly can be exploited without authentication via publicly reachable AJAX actions.

References