CVE-2026-96347: WordPress Bookly plugin <= 28.2 - Insecure Direct Object References (IDOR) vulnerability
Published Sep 30, 2026
·Updated
Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions.
Affected Software
1 affected component
Bookly Bookly plugin<=28.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Bookly pluginto a version that resolves this vulnerability.Fixed in 28.3
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A user with the Subscriber role can exploit the insecure direct object reference vulnerability. The attack can be performed over the network and does not require user interaction.
2
What security impact is indicated?
The vulnerability has an integrity impact rated High, meaning successful exploitation could allow unauthorized modification of data. No confidentiality or availability impact is indicated by the provided vector.
3
Which Bookly versions are affected?
Bookly versions 28.2 and earlier are affected according to the available information.