logo

CVE-2026-5513: Bookly WordPress Plugin Stored XSS via Cookie

ID: 20da1de1-535c-59da-b138-7e440a387e78

STIX ID: report--20da1de1-535c-59da-b138-7e440a387e78

Feed Name: CosmicBytez Labs

Threat Score
60/100

Date Published: 2026-06-14

Date Updated: 2026-06-14

...
...

A stored XSS vulnerability (CVE-2026-5513, CVSS 7.2) in the Bookly WordPress plugin (≤27.2) allows an unauthenticated attacker to set a malicious bookly-customer-full-name cookie that executes in an administrator's browser when viewing booking data; impacts include session hijacking, credential theft, and potential site compromise. The report provides a PoC, affected components, and recommended immediate actions (update plugin, monitor logs, enable WAF/CSP, restrict admin access).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.