Stored Cross-Site Scripting in Bookly Appointment Booking System for WordPress
CVE-2026-5513

7.2HIGH

What is CVE-2026-5513?

The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping via the 'bookly-customer-full-name' cookie. This vulnerability allows unauthenticated attackers to inject malicious scripts into pages, which may execute when a user accesses an affected page. This exploitation can occur if the 'Remember personal information in cookies' feature is enabled, which is typically disabled by default. Users of affected versions should consider upgrading to mitigate risks.

Affected Version(s)

Online Scheduling and Appointment Booking System – Bookly 0 <= 27.2

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Naoya Takahashi
.