« Volver al listado

Booking-wp-plugin

Booking-wp-plugin Bookly: vulnerabilidades y CVE

Booking-wp-plugin Bookly tiene 25 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE25
Últimos 12 meses17
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-96348Alta (7.5)0.35%—30 sept 2026
Unauthenticated Broken Access Control in Bookly <= 28.2 versions.
CVE-2026-96347Media (6.5)0.30%—30 sept 2026
Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions.
CVE-2026-86838Media (5.3)0.22%—28 sept 2026
The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book…
CVE-2026-86837Media (5.3)0.18%—25 sept 2026
The Bookly WordPress plugin before 28.3 does not properly verify a customer's identity before updating their stored details, allowing unauthenticated attackers who know a customer's primary identifier to overwrite that…
CVE-2026-93399Crítica (9.1)0.37%—25 sept 2026
The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and…
CVE-2026-92799Media (5.3)0.32%—25 sept 2026
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in all versions up to, and including, 28.2. This is due to the…
CVE-2026-89063Alta (7.5)1.6%—16 sept 2026
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.1 via the 'conversation_id' parameter due to…
CVE-2026-2520Media (5.4)0.21%—8 sept 2026
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'updateAddon' function in all versions up…
CVE-2026-13424Alta (7.2)0.58%—16 ago 2026
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action in all versions up to, and including, 27.7…
CVE-2026-12905Media (4.3)0.39%—16 ago 2026
The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via the appointment() method of the Mobile Staff Cabinet API (resource=appointment,…
CVE-2026-14516Alta (7.5)0.48%—28 jul 2026
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injection via the 'staff_ids' parameter in all versions up to, and including, 27.5 due to insufficient…
CVE-2026-61949Crítica (9.3)0.40%—23 jul 2026
Unauthenticated SQL Injection in Bookly <= 27.7 versions.
CVE-2026-61944Alta (7.1)0.25%—23 jul 2026
Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.
CVE-2026-42667Alta (7.5)0.42%—15 jun 2026
Unauthenticated Sensitive Data Exposure in Bookly <= 27.4 versions.
CVE-2026-5513Alta (7.2)0.32%—13 jun 2026
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-customer-full-name' cookie in versions up to, and including, 27.2 due to…
CVE-2026-2519Media (5.3)0.45%—9 abr 2026
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation via the 'tips' parameter in all versions up to, and including, 27.0. This is due to the plugin…
CVE-2026-32540Alta (7.1)0.25%—25 mar 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bookly Bookly bookly-responsive-appointment-booking-tool allows Reflected XSS.This issue affects Bookly: from n/a…
CVE-2024-5584Media (6.4)0.31%—11 jun 2024
The WordPress Online Booking and Scheduling Plugin – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Color Profile parameter in all versions up to, and including, 23.2 due to…
CVE-2023-26526Alta (7.7)0.91%—17 may 2024
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Nota-Info Bookly allows Path Traversal, Manipulating Web Input to File System Calls.This issue affects Bookly: from n/a…
CVE-2023-5209Media (4.8)0.45%—27 nov 2023
The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site…
CVE-2023-4691Alta (7.2)0.72%—16 oct 2023
The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high…
CVE-2023-1159Media (4.8)0.37%—2 jun 2023
The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via service titles in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. This makes it possible…
CVE-2023-1172Media (6.1)0.46%—17 mar 2023
The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the full name value in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. This makes it…
CVE-2021-24930Media (5.4)0.62%—6 dic 2021
The WordPress Online Booking and Scheduling Plugin WordPress plugin before 20.3.1 does not escape the Staff Full Name field before outputting it back in a page, which could lead to a Stored Cross-Site Scripting issue
CVE-2018-6891Media (6.1)1.00%—11 feb 2018
Bookly #1 WordPress Booking Plugin Lite before 14.5 has XSS via a jQuery.ajax request to ng-payment_details_dialog.js.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application11
  2. T1059.007 JavaScript4
  3. T1005 Data from Local System3
  4. T1189 Drive-by Compromise2
  5. T1078 Valid Accounts1
  6. T1098.002 Additional Email Delegate Permissions1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.