CVE-2026-12905 | Ladela Bookly Plugin up to 27.7 on WordPress Mobile Staff Cabinet API Handler1_0.php appointment ID resource injection
A vulnerability labeled as problematic has been found in Ladela Bookly Plugin up to 27.7 on WordPress. Affected by this vulnerability is the function appointment of the file frontend/modules/mobile_staff_cabinet/api/handlers/Handler1_0.php of the component Mobile Staff Cabinet API. Executing a manipulation of the argument ID can lead to improper control of resource identifiers.
This vulnerability is tracked as CVE-2026-12905. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More