CVE-2026-96348HIGH NVDCVSS Score 7.5Severity HIGHPublished Sep 30, 2026Vendor unknownDescriptionUnauthenticated Broken Access Control in Bookly <= 28.2 versions.Referenceshttps://patchstack.com/database/wordpress/plugin/bookly-responsive-appointment-booking-tool/vulnerability/wordpress-bookly-plugin-28-2-broken-access-control-vulnerability?_s_id=cve