WordPress Bookly是WordPress基金会开源的一款提供预约管理功能的CMS插件。 WordPress Bookly 27.7及之前版本存在跨站脚本漏洞,该漏洞源于bookly_speed_up_update_addons AJAX操作输入清理和输出转义不足,可能导致未经身份验证的攻击者注入任意Web脚本,当管理员查看Diagnostics → Logs页面时执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ladela | Online Scheduling and Appointment Booking System – Bookly | ≤ 27.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ladela | Online Scheduling and Appointment Booking System – Bookly | 0 ~ 27.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC'
test'