Post
OffSequence
offseq.bsky.social
did:plc:t5t6qep2vfipbi7f54demwev
Bookly plugin for WordPress (≤28.2) has a CRITICAL auth bypass (CVE-2026-93399). Unauth'd attackers can access & delete bookings. No patch — restrict plugin access & monitor for abuse. https://radar.offseq.com/threat/cve-2026-93399-cwe-639-authorization-bypass-through-user-controlled-key-in-ladel...
https://radar.offseq.com/threat/cve-2026-93399-cwe-639-authorization-bypass-through-user-controlled-key-in-ladela-online-scheduling-437a419f1c3d5ec6
2026-09-25T10:30:28.061Z