Junglewise Threat Intelligence

CVE-2026-61944: Bookly WordPress plugin unauthenticated XSS

CVE-2026-61944 · Severity: high · CVSS 7.1 · Published 2026-07-23

Technologies: Bookly. Vendors: Bookly.

Executive brief

Bookly is a popular WordPress plugin used by businesses to manage automated appointment scheduling and bookings. A security flaw in this plugin allows attackers to inject malicious scripts into the website, which could lead to unauthorized redirects, theft of user session data, or the display of fraudulent content to site visitors. This vulnerability can be exploited without needing a password, though it requires a victim to interact with a malicious link or page.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Bookly (Responsive Appointment Booking Tool) plugin for WordPress due to improper neutralization of input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript or HTML payloads. Successful exploitation requires a user to perform an action, such as clicking a specially crafted link (User Interaction). Because the vulnerability has a 'Changed' scope (S:C), an attacker could potentially access sensitive information like session cookies or perform actions on behalf of an authenticated administrator. The issue is resolved in version 27.8.

Affected products

  • Bookly Bookly (Responsive Appointment Booking Tool) <= 27.7

Timeline

  • 2026-01-22: other: Vulnerability reported by researcher ickogz
  • 2026-07-16: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: CVE published to NVD

References

Related threats