CVE · Medium

CVE-2023-1159 — Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 21.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-1159 Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 21.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 21.8 21.8 2023-06-01

CVE-2023-1159

The Bookly appointment scheduling plugin for WordPress contains a stored cross-site scripting vulnerability in versions 21.5 and earlier that stems from inadequate sanitization of service titles and insufficient escaping of output. An authenticated administrator can inject malicious scripts into service titles, which then execute when other users view affected pages. This vulnerability is limited to WordPress multisite setups or installations where the unfiltered_html capability has been disabled.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.