CVE-2026-13424

Online Scheduling and Appointment Booking System <= 27.7 - Unauthenticated Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action in all versions up to, and including, 27.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injection point is the bookly_speed_up_update_addons AJAX action, which is registered as wp_ajax_nopriv_* and therefore reachable without authentication; the payload is stored verbatim in the bookly_log.details column when a request is submitted without a valid signature, and executes when an administrator later views the Diagnostics → Logs page.


We have discovered 9,745 live websites that are affected by CVE-2026-13424.

Run a Free Instant Scan




Affected Software

Product  Bookly
Category Appointment Scheduling
Vulnerable Domains9,745 live websites (83% of Bookly install base)
Vulnerable Versions
  • from 0 through 27.7
Vulnerable Versions Count122 versions ( 98% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 16, 2026
  • Updated - Aug 17, 2026

Credits

  • Dmitrii Ignatyev (finder)

Website Distribution by Country

Number of websites using CVE-2026-13424
United States2,386 websites



Germany1,028 websites
France890 websites
Netherlands629 websites
GB495 websites
Spain472 websites
Italy428 websites
Canada242 websites
Switzerland242 websites
Belgium215 websites

Website Distribution by TLD

Number of websites using CVE-2026-13424
.com3,646 websites
.de648 websites
.nl611 websites
.fr501 websites
.co.uk355 websites
.it353 websites
.org272 websites
.es212 websites
.ch202 websites
.be191 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-13424

Top websites that are affected by CVE-2026-13424. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.com Singapore**,***
***********.com United States**,***
*****************.com Germany**,***
****.*******.net United States**,***
******.com Estonia***,***
****.ru Russia***,***
*************.io Romania***,***
****************.ro Romania***,***
***********.com Japan***,***
**************.com Italy***,***
See full domain list

FAQ

CVE-2026-13424 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Bookly
A total of 9,745 websites have been identified as vulnerable to CVE-2026-13424, based on global website indexing conducted by WebTechSurvey.
The Bookly is affected by the CVE-2026-13424 vulnerability.
Bookly versions up to and including 27.7 are vulnerable to CVE-2026-13424.

References