A vulnerability categorized as problematic has been discovered in ladela Online Scheduling and Appointment Booking System Plugin up to 27.2 on WordPress. Impacted is an unknown function of the component setting Handler. Such manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2026-5513. The attack can be executed remotely. There is not any exploit available.