Booking-wp-plugin

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 6
    Known Exploited: 0
    0
    Critical Level Threats
    2
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-5209

    Bookly < 22.5 - Admin+ Stored XSS

    Last Modified: Nov 21, 2024
    Published: Nov 27, 2023

    CVE-2023-4691

    Bookly < 22.4 - Admin+ SQLi

    Last Modified: Apr 23, 2025
    Published: Oct 16, 2023

    CVE-2023-1159

    The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via service titles in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Last Modified: Dec 20, 2024
    Published: Jun 02, 2023

    CVE-2023-1172

    The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the full name value in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Last Modified: Jan 13, 2025
    Published: Mar 17, 2023

    CVE-2021-24930

    Bookly < 20.3.1 - Staff Member Stored Cross-Site Scripting

    Last Modified: Nov 21, 2024
    Published: Dec 06, 2021
    Items Per Page
    Booking-Wp-Plugin Vulnerabilities & Security CVEs | CVE-DB