Impact
An improperly sanitized input in the WpBookingly WordPress plugin allows an attacker to embed malicious scripts into responses displayed to site visitors. This vulnerability, categorized as CWE-79, can result in the execution of arbitrary JavaScript in the context of the affected site. Because the script runs with the privileges of the visiting user, an attacker may steal session cookies, manipulate page content, or redirect users to malicious sites.
Affected Systems
The flaw affects WordPress sites that utilize the magepeopleteam WpBookingly plugin version 1.3.2 or earlier. Any website delivering booking or service‑management pages via this plugin is potentially compromised until the plugin is upgraded to at least 1.4.0.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk level. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no public exploitation evidence at this time. Based on the description it is inferred that the attacker can trigger the flaw by directing a victim to a crafted URL or input that the plugin fails to sanitize, making the XSS a surface‑level risk that does not require privileged access.
OpenCVE Enrichment