CVE-2026-93399 is an unauthenticated insecure direct object reference vulnerability in the Bookly scheduling and appointment-booking plugin for WordPress through version 28.2. The booking-form initialization AJAX handler stores an attacker-supplied order identifier in a new booking session. Subsequent AJAX handlers trust that identifier without confirming that the active session created or is authorized to access the referenced order. An attacker can enumerate sequential order identifiers to obtain booking-order secret tokens, access associated calendar or appointment information, and roll back arbitrary bookings that have not been completed.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This six-file repository is a standalone Python 3 proof-of-concept/exploitation utility for CVE-2026-93399, an unauthenticated CWE-639 IDOR in the Bookly WordPress plugin through version 28.2. The primary and only code file, poc.py, uses requests and urllib3 to normalize targets, fingerprint the plugin from publicly accessible plugin files, compare discovered versions against 28.2, and communicate with the target's WordPress AJAX endpoint. The core attack supplies a chosen order ID to bookly_get_form_id, then uses bookly_render_complete to disclose the corresponding secret booking token without proving ownership of the order. The tool supports a non-destructive check mode, order-ID ranges/enumeration, concurrent list-based scanning, JSONL/hit-list output, optional proxying, and an exploit mode that can retrieve appointment calendar data or perform a confirmed destructive booking rollback. README.md documents commands, FOFA discovery signatures, impact, and the deletion warning; requirements.txt lists requests and urllib3; targets.example.txt supplies a sample target. No shell, code-execution, persistence, or malware payload is present.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated insecure direct object reference vulnerability in the Bookly WordPress plugin through version 28.2. Attackers can enumerate sequential order IDs to obtain other customers' secret order tokens, access appointment/calendar information, and permanently delete arbitrary non-completed bookings.
A critical unauthenticated insecure direct object reference vulnerability in the Bookly WordPress appointment-booking plugin through version 28.2. Attacker-controlled order IDs can be used to expose booking tokens and appointment data and delete non-completed bookings, including associated appointment records.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.