CVE Database /
CVE-2023-1159
CVE · Medium
CVE-2023-1159 — Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 21.8
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-1159
|
Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 21.8 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
4.8
|
< 21.8
|
21.8 |
2023-06-01 |
—
|
CVE-2023-1159
The Bookly appointment scheduling plugin for WordPress contains a stored cross-site scripting vulnerability in versions 21.5 and earlier that stems from inadequate sanitization of service titles and insufficient escaping of output. An authenticated administrator can inject malicious scripts into service titles, which then execute when other users view affected pages. This vulnerability is limited to WordPress multisite setups or installations where the unfiltered_html capability has been disabled.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings