PT-2026-49091 · WordPress · Bookly

·

CVE-2026-5513

·

Published

2026-06-13

·

Updated

2026-06-16

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bookly versions prior to 27.3
Description The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress contains a Stored Cross-Site Scripting issue. This occurs due to insufficient input sanitization and output escaping related to the bookly-customer-full-name cookie. Unauthenticated attackers can inject arbitrary web scripts into pages, which execute when a user accesses the affected page. This issue is only exploitable if the 'Remember personal information in cookies' setting is enabled.
Recommendations Update to a version later than 27.2. Disable the 'Remember personal information in cookies' setting to mitigate the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5513

Affected Products

Bookly