PLUGIN SECURITY

Is Bookly Responsive Appointment Booking Tool safe?

Appointment booking system for WordPress — schedule appointments, manage calendars, send reminders, take payments. Start booking today!

What this plugin does

  • Slug: bookly-responsive-appointment-booking-tool
  • Author: Bookly
  • 60000+ active installs
  • 88/100 rating (575 reviews on wordpress.org)
  • 3907185 all-time downloads
  • On WordPress.org since 2014-10-10

appointment bookingappointmentsbookingbooking calendarbooking system

Maintenance status

  • Latest known version: 28.0
  • Last updated: 2026-08-25 11:30am GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 5.3.7+
  • Max supported PHP (analyzed): <8.0

Known vulnerabilities

18 known CVEs on file for Bookly Responsive Appointment Booking Tool.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12905 Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 28.0 Authorization Bypass Through User-Controlled Key Medium 4.3 < 28.0 28.0 2026-08-15 ✓ fixed in latest
CVE-2026-13424 Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 28.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.2 < 28.0 28.0 2026-08-15 ✓ fixed in latest
CVE-2026-13395 Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 27.8 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Unknown < 27.8 27.8 2026-07-30 ✓ fixed in latest
CVE-2026-14516 Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] <= 27.5 (unfixed) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.5 < 27.8 27.8 2026-07-16 ✓ fixed in latest
CVE-2026-5513 Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 27.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.2 < 27.3 27.3 2026-06-12 ✓ fixed in latest
CVE-2026-42667 Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 27.5 Insertion of Sensitive Information Into Sent Data High 7.5 < 27.5 27.5 2026-05-10 ✓ fixed in latest
CVE-2026-32540 Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 26.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 26.8 26.8 2026-03-20 ✓ fixed in latest
CVE-2024-5584 Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 23.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 23.3 23.3 2024-06-10 ✓ fixed in latest
+ 13 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-5209 Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 22.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 22.5 22.5 2023-11-06 ✓ fixed in latest
CVE-2023-4691 Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 22.4 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.2 < 22.4 22.4 2023-09-25 ✓ fixed in latest
CVE-2023-1159 Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 21.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 21.8 21.8 2023-06-01 ✓ fixed in latest
CVE-2023-26526 Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 21.8 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 7.7 < 21.8 21.8 2023-05-11 ✓ fixed in latest
CVE-2023-1172 Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 21.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 21.6 21.6 2023-03-17 ✓ fixed in latest
CVE-2021-24930 Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 20.3.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 20.3.1 20.3.1 2021-11-08 ✓ fixed in latest
CVE-2018-6891 Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 14.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 14.6 14.6 2018-02-10 ✓ fixed in latest
Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 27.1 Unknown < 27.1 27.1 0000-00-00 ✓ fixed in latest
Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 27.8 Unknown < 27.8 27.8 0000-00-00 ✓ fixed in latest
Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 27.8 Unknown < 27.8 27.8 0000-00-00 ✓ fixed in latest
CVE-2026-2519 Bookly < 27.1 - Unauthenticated Price Manipulation via 'tips' Unknown < 27.1 27.1 ✓ fixed in latest
CVE-2026-61944 Online Scheduling and Appointment Booking System – Bookly < 27.8 - Unauthenticated Stored Cross-Site Scripting Unknown < 27.8 27.8 ✓ fixed in latest
CVE-2026-61949 Online Scheduling and Appointment Booking System – Bookly < 27.8 - Unauthenticated SQL Injection Unknown < 27.8 27.8 ✓ fixed in latest

How to fix it

Keep Bookly Responsive Appointment Booking Tool updated — 28.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.