Medium severity6.1NVD Advisory· Published Feb 11, 2018· Updated Jun 17, 2026
CVE-2018-6891
CVE-2018-6891
Description
Bookly #1 WordPress Booking Plugin Lite before 14.5 has XSS via a jQuery.ajax request to ng-payment_details_dialog.js.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- www.gubello.me/blog/bookly-blind-stored-xss/nvdExploitThird Party Advisory
- wordpress.org/plugins/bookly-responsive-appointment-booking-tool/nvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.