Critical Bookly IDOR Leads to Booking Disclosure and Deletion (CVE-2026-93399)
During independent security research conducted as part of the Wordfence Bug Bounty Program, we identified an unauthenticated Insecure Direct Object Reference (IDOR) vulnerability in Bookly, a WordPress appointment booking plugin used to manage online scheduling, services, staff availability and customer appointments.