WordPress Plugin Vulnerabilities
Bookly #1 WordPress Booking Plugin (Lite) < 14.5 – Unauthenticated Blind Stored XSS
Description
An unauthenticated user can inject arbitrary persistent javascript code in the admin panel via Bookly plug-in.
Affects Plugins
References
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Submitter
Luigi
Submitter website
Verified
No
WPVDB ID
Timeline
Publicly Published
2018-02-10 (about 7 years ago)
Added
2018-02-13 (about 7 years ago)
Last Updated
2020-10-02 (about 5 years ago)