{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/online-scheduling-and-appointment-booking-system--bookly/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-13424"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Online Scheduling and Appointment Booking System – Bookly"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Bookly"],"content_html":"\u003cp\u003eThe Bookly WordPress plugin (versions 27.7 and earlier) is vulnerable to a stored Cross-Site Scripting (XSS) attack. This vulnerability arises from insufficient input sanitization and output escaping within the 'bookly_speed_up_update_addons' AJAX action. Because this action is registered as 'wp_ajax_nopriv', it is accessible to unauthenticated attackers.\u003c/p\u003e\n\u003cp\u003eAn attacker can submit a crafted AJAX request to the plugin that lacks a valid signature. The plugin stores the malicious input within the 'bookly_log' table in the 'details' column. The payload executes in the browser of any administrator who navigates to the 'Diagnostics → Logs' page within the WordPress dashboard. This facilitates administrative session hijacking, unauthorized configuration changes, or the execution of arbitrary JavaScript within the context of the WordPress admin panel. Defenders should prioritize updating to the patched version once available and monitor logs for anomalous AJAX requests to the vulnerable endpoint.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site running a vulnerable version of the Bookly plugin (\u0026lt;= 27.7).\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP POST request targeting the 'wp-admin/admin-ajax.php' endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker sets the 'action' parameter to 'bookly_speed_up_update_addons'.\u003c/li\u003e\n\u003cli\u003eAttacker inserts a JavaScript payload into the request parameters intended for the 'details' field.\u003c/li\u003e\n\u003cli\u003eThe plugin fails to validate the request signature and writes the unsanitized payload into the 'bookly_log' table.\u003c/li\u003e\n\u003cli\u003eAn administrator accesses the 'Diagnostics → Logs' page in the WordPress admin dashboard.\u003c/li\u003e\n\u003cli\u003eThe browser renders the stored JavaScript payload, executing it in the administrator's security context.\u003c/li\u003e\n\u003cli\u003eAttacker leverages the hijacked administrative session to further compromise the WordPress site.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to achieve Stored XSS against WordPress administrators. This can lead to full administrative account takeover, site defacement, unauthorized plugin installation, or redirection of site visitors to malicious infrastructure, significantly impacting the integrity and availability of the web application.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Bookly plugin to the latest version immediately once a patch is provided by the vendor.\u003c/li\u003e\n\u003cli\u003eImplement WAF rules to detect and block POST requests to 'admin-ajax.php' containing the 'action=bookly_speed_up_update_addons' parameter and suspicious script-related characters.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule below to monitor for exploitation attempts targeting the vulnerable AJAX action.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-16T08:24:45Z","date_published":"2026-08-16T08:24:45Z","id":"https://feed.craftedsignal.io/briefs/2026-08-bookly-xss/","summary":"The Bookly WordPress plugin contains a stored XSS vulnerability via the bookly_speed_up_update_addons AJAX action, allowing unauthenticated attackers to inject malicious scripts that execute in an administrator's browser.","title":"Stored XSS Vulnerability in Bookly WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-bookly-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Online Scheduling and Appointment Booking System – Bookly","version":"https://jsonfeed.org/version/1.1"}