CVE · High

CVE-2023-26526 — Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 21.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-26526 Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 21.8 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 7.7 < 21.8 21.8 2023-05-11

CVE-2023-26526

The Bookly appointment scheduling plugin prior to version 21.8 contains an arbitrary file deletion flaw that permits attackers to remove files from affected websites. Successfully exploiting this vulnerability could result in the deletion of critical system files, potentially rendering the site inoperable. The vendor has not released a patch or responded to notifications about this issue as of the advisory date.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.