CVE-2026-32540: WordPress Bookly plugin <= 26.7 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bookly Bookly bookly-responsive-appointment-booking-tool allows Reflected XSS.This issue affects Bookly: from n/a through <= 26.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32540?
CVE-2026-32540 is classified as a high-severity vulnerability due to its potential for exploiting reflected cross-site scripting (XSS).
How do I fix CVE-2026-32540?
To fix CVE-2026-32540, update the Bookly plugin to version 26.8 or later to address the reflected XSS vulnerability.
What type of vulnerability is CVE-2026-32540?
CVE-2026-32540 is a reflected cross-site scripting (XSS) vulnerability that allows an attacker to inject malicious scripts into a web page.
Which versions of Bookly are affected by CVE-2026-32540?
CVE-2026-32540 affects all versions of the Bookly plugin up to and including version 26.7.
What can happen if CVE-2026-32540 is exploited?
If CVE-2026-32540 is exploited, it can allow attackers to execute arbitrary JavaScript in the context of a victim's session, potentially leading to data theft or account hijacking.