A vulnerability described as problematic has been identified in ladela Bookly Plugin up to 27.7 on WordPress. This vulnerability affects the function bookly_speed_up_update_addons. Such manipulation leads to cross site scripting.

This vulnerability is referenced as CVE-2026-13424. It is possible to launch the attack remotely. No exploit is available.