CVE Database /
CVE-2023-26526
CVE · High
CVE-2023-26526 — Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 21.8
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-26526
|
Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 21.8 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
High
7.7
|
< 21.8
|
21.8 |
2023-05-11 |
—
|
CVE-2023-26526
The Bookly appointment scheduling plugin prior to version 21.8 contains an arbitrary file deletion flaw that permits attackers to remove files from affected websites. Successfully exploiting this vulnerability could result in the deletion of critical system files, potentially rendering the site inoperable. The vendor has not released a patch or responded to notifications about this issue as of the advisory date.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings