THREAT OPS › Threat News › [NVD] CVE-2026-12905 (MEDIUM 4.3) — The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via the appointment() method of the Mobile Staff Cabinet API (resource=appointment, action=bookly_mobile_staff_cabinet) in frontend/modules/mobile_staff_cabine
[NVD] CVE-2026-12905 (MEDIUM 4.3) — The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via the appointment() method of the Mobile Staff Cabinet API (resource=appointment, action=bookly_mobile_staff_cabinet) in frontend/modules/mobile_staff_cabine
CVE-2026-12905 CVSS: 4.3 MEDIUM Published: 2026-08-16T05:16:45.947
The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via the appointment() method of the Mobile Staff Cabinet API (resource=appointment, action=bookly_mobile_staff_cabinet) in frontend/modules/mobile_staff_cabinet/api/handlers/Handler1_0.php. This is due to the ha
Indicators of compromise
- CVE-2026-12905cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-12905