Stored Cross-Site Scripting in Bookly Appointment Booking System for WordPress
CVE-2026-5513
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 June 2026
What is CVE-2026-5513?
The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping via the 'bookly-customer-full-name' cookie. This vulnerability allows unauthenticated attackers to inject malicious scripts into pages, which may execute when a user accesses an affected page. This exploitation can occur if the 'Remember personal information in cookies' feature is enabled, which is typically disabled by default. Users of affected versions should consider upgrading to mitigate risks.
Affected Version(s)
Online Scheduling and Appointment Booking System β Bookly 0 <= 27.2