Input validation vulnerability in WordPress Online Booking and Scheduling Plugin – Bookly 21.7

The Bookly plugin for WordPress is vulnerable to a type of attack called Stored Cross-Site Scripting. This means that versions up to and including 21.5 of the plugin are not secure enough to prevent malicious attackers from injecting web scripts into pages that are accessed by users. This kind of attack only affects multi-site installations and installations where certain security features have been disabled.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.