cleantalk
Vulnerabilities and Security Researches

WordPress Online Booking and Scheduling Plugin – Bookly, CVE-2021-24930

CVE, Research URL

CVE-2021-24930

Published on
Dec 06, 2021
Research Description
The WordPress Online Booking and Scheduling Plugin WordPress plugin before 20.3.1 does not escape the Staff Full Name field before outputting it back in a page, which could lead to a Stored Cross-Site Scripting issue
Affected versions
max 20.3.1.
Status
vulnerable