CVE · Medium

CVE-2021-24930 — Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 20.3.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24930 Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 20.3.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 20.3.1 20.3.1 2021-11-08

CVE-2021-24930

The Bookly WordPress plugin before version 20.3.1 contains a stored cross-site scripting vulnerability in the Staff Full Name field. The plugin fails to properly sanitize this field before displaying it on pages, allowing attackers to inject malicious scripts that will execute for all users viewing the affected content. This vulnerability could compromise user sessions and site security through persistent XSS attacks.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.