Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-24930 1 Booking-wp-plugin 1 Bookly 2024-11-21 5.4 Medium
The WordPress Online Booking and Scheduling Plugin WordPress plugin before 20.3.1 does not escape the Staff Full Name field before outputting it back in a page, which could lead to a Stored Cross-Site Scripting issue
CVE-2018-6891 1 Booking-wp-plugin 1 Bookly 2024-11-21 6.1 Medium
Bookly #1 WordPress Booking Plugin Lite before 14.5 has XSS via a jQuery.ajax request to ng-payment_details_dialog.js.