Booking-wp-plugin
Booking-wp-plugin Bookly: vulnerabilidades y CVE
Booking-wp-plugin Bookly tiene 25 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE25
Últimos 12 meses17
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-96348 | Alta (7.5) | 0.35% | — | 30 sept 2026 | Unauthenticated Broken Access Control in Bookly <= 28.2 versions. |
| CVE-2026-96347 | Media (6.5) | 0.30% | — | 30 sept 2026 | Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions. |
| CVE-2026-86838 | Media (5.3) | 0.22% | — | 28 sept 2026 | The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book… |
| CVE-2026-86837 | Media (5.3) | 0.18% | — | 25 sept 2026 | The Bookly WordPress plugin before 28.3 does not properly verify a customer's identity before updating their stored details, allowing unauthenticated attackers who know a customer's primary identifier to overwrite that… |
| CVE-2026-93399 | Crítica (9.1) | 0.37% | — | 25 sept 2026 | The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and… |
| CVE-2026-92799 | Media (5.3) | 0.32% | — | 25 sept 2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in all versions up to, and including, 28.2. This is due to the… |
| CVE-2026-89063 | Alta (7.5) | 1.6% | — | 16 sept 2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.1 via the 'conversation_id' parameter due to… |
| CVE-2026-2520 | Media (5.4) | 0.21% | — | 8 sept 2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'updateAddon' function in all versions up… |
| CVE-2026-13424 | Alta (7.2) | 0.58% | — | 16 ago 2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action in all versions up to, and including, 27.7… |
| CVE-2026-12905 | Media (4.3) | 0.39% | — | 16 ago 2026 | The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via the appointment() method of the Mobile Staff Cabinet API (resource=appointment,… |
| CVE-2026-14516 | Alta (7.5) | 0.48% | — | 28 jul 2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injection via the 'staff_ids' parameter in all versions up to, and including, 27.5 due to insufficient… |
| CVE-2026-61949 | Crítica (9.3) | 0.40% | — | 23 jul 2026 | Unauthenticated SQL Injection in Bookly <= 27.7 versions. |
| CVE-2026-61944 | Alta (7.1) | 0.25% | — | 23 jul 2026 | Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions. |
| CVE-2026-42667 | Alta (7.5) | 0.42% | — | 15 jun 2026 | Unauthenticated Sensitive Data Exposure in Bookly <= 27.4 versions. |
| CVE-2026-5513 | Alta (7.2) | 0.32% | — | 13 jun 2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-customer-full-name' cookie in versions up to, and including, 27.2 due to… |
| CVE-2026-2519 | Media (5.3) | 0.45% | — | 9 abr 2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation via the 'tips' parameter in all versions up to, and including, 27.0. This is due to the plugin… |
| CVE-2026-32540 | Alta (7.1) | 0.25% | — | 25 mar 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bookly Bookly bookly-responsive-appointment-booking-tool allows Reflected XSS.This issue affects Bookly: from n/a… |
| CVE-2024-5584 | Media (6.4) | 0.31% | — | 11 jun 2024 | The WordPress Online Booking and Scheduling Plugin – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Color Profile parameter in all versions up to, and including, 23.2 due to… |
| CVE-2023-26526 | Alta (7.7) | 0.91% | — | 17 may 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Nota-Info Bookly allows Path Traversal, Manipulating Web Input to File System Calls.This issue affects Bookly: from n/a… |
| CVE-2023-5209 | Media (4.8) | 0.45% | — | 27 nov 2023 | The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site… |
| CVE-2023-4691 | Alta (7.2) | 0.72% | — | 16 oct 2023 | The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high… |
| CVE-2023-1159 | Media (4.8) | 0.37% | — | 2 jun 2023 | The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via service titles in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. This makes it possible… |
| CVE-2023-1172 | Media (6.1) | 0.46% | — | 17 mar 2023 | The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the full name value in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. This makes it… |
| CVE-2021-24930 | Media (5.4) | 0.62% | — | 6 dic 2021 | The WordPress Online Booking and Scheduling Plugin WordPress plugin before 20.3.1 does not escape the Staff Full Name field before outputting it back in a page, which could lead to a Stored Cross-Site Scripting issue |
| CVE-2018-6891 | Media (6.1) | 1.00% | — | 11 feb 2018 | Bookly #1 WordPress Booking Plugin Lite before 14.5 has XSS via a jQuery.ajax request to ng-payment_details_dialog.js. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.