CVE Database /
CVE-2021-24930
CVE · Medium
CVE-2021-24930 — Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 20.3.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24930
|
Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 20.3.1 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 20.3.1
|
20.3.1 |
2021-11-08 |
—
|
CVE-2021-24930
The Bookly WordPress plugin before version 20.3.1 contains a stored cross-site scripting vulnerability in the Staff Full Name field. The plugin fails to properly sanitize this field before displaying it on pages, allowing attackers to inject malicious scripts that will execute for all users viewing the affected content. This vulnerability could compromise user sessions and site security through persistent XSS attacks.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings