PLUGIN SECURITY
Is Bookly Responsive Appointment Booking Tool safe?
Appointment booking system for WordPress — schedule appointments, manage calendars, send reminders, take payments. Start booking today!
What this plugin does
- Slug:
bookly-responsive-appointment-booking-tool - Author: Bookly
- 60000+ active installs
- 88/100 rating (575 reviews on wordpress.org)
- 3907185 all-time downloads
- On WordPress.org since 2014-10-10
appointment bookingappointmentsbookingbooking calendarbooking system
Maintenance status
- Latest known version: 28.0
- Last updated: 2026-08-25 11:30am GMT
- Tested up to WordPress: 7.1
- Requires PHP: 5.3.7+
- Max supported PHP (analyzed): <8.0
Known vulnerabilities
18 known CVEs on file for Bookly Responsive Appointment Booking Tool.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-12905 | Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 28.0 | Authorization Bypass Through User-Controlled Key | Medium 4.3 | < 28.0 | 28.0 | 2026-08-15 | ✓ fixed in latest |
| CVE-2026-13424 | Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 28.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.2 | < 28.0 | 28.0 | 2026-08-15 | ✓ fixed in latest |
| CVE-2026-13395 | Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 27.8 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Unknown | < 27.8 | 27.8 | 2026-07-30 | ✓ fixed in latest |
| CVE-2026-14516 | Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] <= 27.5 (unfixed) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.5 | < 27.8 | 27.8 | 2026-07-16 | ✓ fixed in latest |
| CVE-2026-5513 | Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 27.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.2 | < 27.3 | 27.3 | 2026-06-12 | ✓ fixed in latest |
| CVE-2026-42667 | Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 27.5 | Insertion of Sensitive Information Into Sent Data | High 7.5 | < 27.5 | 27.5 | 2026-05-10 | ✓ fixed in latest |
| CVE-2026-32540 | Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 26.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 26.8 | 26.8 | 2026-03-20 | ✓ fixed in latest |
| CVE-2024-5584 | Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 23.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 23.3 | 23.3 | 2024-06-10 | ✓ fixed in latest |
+ 13 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2023-5209 | Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 22.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 22.5 | 22.5 | 2023-11-06 | ✓ fixed in latest |
| CVE-2023-4691 | Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 22.4 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.2 | < 22.4 | 22.4 | 2023-09-25 | ✓ fixed in latest |
| CVE-2023-1159 | Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 21.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 21.8 | 21.8 | 2023-06-01 | ✓ fixed in latest |
| CVE-2023-26526 | Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 21.8 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 7.7 | < 21.8 | 21.8 | 2023-05-11 | ✓ fixed in latest |
| CVE-2023-1172 | Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 21.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 21.6 | 21.6 | 2023-03-17 | ✓ fixed in latest |
| CVE-2021-24930 | Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 20.3.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 20.3.1 | 20.3.1 | 2021-11-08 | ✓ fixed in latest |
| CVE-2018-6891 | Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 14.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 14.6 | 14.6 | 2018-02-10 | ✓ fixed in latest |
| — | Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 27.1 | — | Unknown | < 27.1 | 27.1 | 0000-00-00 | ✓ fixed in latest |
| — | Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 27.8 | — | Unknown | < 27.8 | 27.8 | 0000-00-00 | ✓ fixed in latest |
| — | Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 27.8 | — | Unknown | < 27.8 | 27.8 | 0000-00-00 | ✓ fixed in latest |
| CVE-2026-2519 | Bookly < 27.1 - Unauthenticated Price Manipulation via 'tips' | — | Unknown | < 27.1 | 27.1 | — | ✓ fixed in latest |
| CVE-2026-61944 | Online Scheduling and Appointment Booking System – Bookly < 27.8 - Unauthenticated Stored Cross-Site Scripting | — | Unknown | < 27.8 | 27.8 | — | ✓ fixed in latest |
| CVE-2026-61949 | Online Scheduling and Appointment Booking System – Bookly < 27.8 - Unauthenticated SQL Injection | — | Unknown | < 27.8 | 27.8 | — | ✓ fixed in latest |
How to fix it
Keep Bookly Responsive Appointment Booking Tool updated — 28.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress — 100000+ active installs — 98/100 (99) — max PHP 8.4
- Booking for Appointments and Events Calendar – Amelia — 90000+ active installs — 92/100 (785)
- Simply Schedule Appointments — 50000+ active installs — 100/100 (155) — max PHP 8.4
- Booking Calendar — 40000+ active installs — 94/100 (653) — max PHP 8.4
- SimplyBook.me – Booking and reservations calendar — 30000+ active installs — 90/100 (17) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.