What is CVE-2026-13424?
A stored XSS vulnerability was found in the Bookly plugin for WordPress via the "bookly_speed_up_update_addons" AJAX action. It affects all versions up to and including 27.7. Administrators should update the plugin to the latest patched version.
Azərbaycanca: WordPress-in Bookly plaqinində "bookly_speed_up_update_addons" AJAX əməliyyatı vasitəsilə saxlanılan XSS zəifliyi aşkarlanıb. Bu, 27.7 versiyasına qədər bütün versiyalara təsir edir. İdarəçilərə plaqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What vulnerability was found in the Bookly plugin for WordPress?
A stored XSS (Cross-Site Scripting) vulnerability was found in the Bookly plugin for WordPress via the "bookly_speed_up_update_addons" AJAX action.
Which versions of the Bookly plugin are affected by CVE-2026-13424?
CVE-2026-13424 affects all versions of the Bookly plugin up to and including version 27.7.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.