THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-12905 (MEDIUM 4.3) — The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via the appointment() method of the Mobile Staff Cabinet API (resource=appointment, action=bookly_mobile_staff_cabinet) in frontend/modules/mobile_staff_cabine

[NVD] CVE-2026-12905 (MEDIUM 4.3) — The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via the appointment() method of the Mobile Staff Cabinet API (resource=appointment, action=bookly_mobile_staff_cabinet) in frontend/modules/mobile_staff_cabine

mednvdPublished 2026-08-16

CVE-2026-12905 CVSS: 4.3 MEDIUM Published: 2026-08-16T05:16:45.947

The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via the appointment() method of the Mobile Staff Cabinet API (resource=appointment, action=bookly_mobile_staff_cabinet) in frontend/modules/mobile_staff_cabinet/api/handlers/Handler1_0.php. This is due to the ha

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-12905