WordPress Plugin Vulnerabilities

Bookly #1 WordPress Booking Plugin (Lite) < 14.5 – Unauthenticated Blind Stored XSS

Description

An unauthenticated user can inject arbitrary persistent javascript code in the admin panel via Bookly plug-in.

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Submitter
Luigi
Submitter website
Verified
No

Timeline

Publicly Published
2018-02-10 (about 7 years ago)
Added
2018-02-13 (about 7 years ago)
Last Updated
2020-10-02 (about 5 years ago)

Other