Stored Cross-Site Scripting Vulnerability in Bookly Online Scheduling Plugin for WordPress
CVE-2026-13424

7.2HIGH

What is CVE-2026-13424?

The Bookly Online Scheduling and Appointment Booking System plugin for WordPress has a vulnerability that allows unauthenticated attackers to exploit the system via the 'bookly_speed_up_update_addons' AJAX action. This issue arises from inadequate input sanitization and output escaping, enabling attackers to inject malicious web scripts. The injected scripts are stored in the database and executed whenever an administrator accesses the Logs page, posing significant risks to site integrity and data security. It is crucial for users to update to the latest version to mitigate these risks.

Affected Version(s)

Online Scheduling and Appointment Booking System – Bookly 0 <= 27.7

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dmitrii Ignatyev
.