CVE-2026-93399 | Bookly Plugin up to 28.2 on WordPress AJAX Actions order_id resource injection
A vulnerability identified as critical has been detected in Bookly Plugin up to 28.2 on WordPress. The impacted element is the function bookly_get_form_id/bookly_render_complete/bookly_add_to_calendar/bookly_rollback_order of the component AJAX Actions. Performing a manipulation of the argument order_id results in improper control of resource identifiers.
This vulnerability is known as CVE-2026-93399. Remote exploitation of the attack is possible. No exploit is available.VulDB Recent EntriesRead More