CVE · High

CVE-2026-13424 — Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 28.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-13424 Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 28.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.2 < 28.0 28.0 2026-08-15

CVE-2026-13424

The Bookly plugin for WordPress, in versions up to 27.7, has a security flaw that allows attackers to inject malicious code into a website. This is due to inadequate protection against tainted input, which allows attackers to inject arbitrary scripts that will run when a user visits a specific page. The vulnerability is triggered through an AJAX action that can be accessed without authentication, and the malicious code is stored in the website's logs, where it can be executed by an administrator when they view the logs.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.