CVE · High

CVE-2026-32540 — Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 26.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-32540 Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 26.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 26.8 26.8 2026-03-20

CVE-2026-32540

The Bookly plugin for WordPress contains a security flaw that allows malicious code injection through URLs, putting users at risk of cross-site scripting attacks without requiring authentication. This vulnerability stems from inadequate filtering of input data and failure to properly encode output in versions 26.7 and earlier. As a result, attackers can exploit this weakness by persuading users to click on a link or perform another action.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.