CVE Database /
CVE-2026-13424
CVE · High
CVE-2026-13424 — Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 28.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-13424
|
Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 28.0 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
High
7.2
|
< 28.0
|
28.0 |
2026-08-15 |
—
|
CVE-2026-13424
The Bookly plugin for WordPress, in versions up to 27.7, has a security flaw that allows attackers to inject malicious code into a website. This is due to inadequate protection against tainted input, which allows attackers to inject arbitrary scripts that will run when a user visits a specific page. The vulnerability is triggered through an AJAX action that can be accessed without authentication, and the malicious code is stored in the website's logs, where it can be executed by an administrator when they view the logs.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings