This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
Suriq - Always on Watch
suriq.io
did:plc:6vjp7fbgz5ductueireifliv
The Bookly WordPress booking plugin (60k+ sites) has an unauthenticated stored XSS flaw, CVE-2026-13424.
Anyone can plant a script that runs when an admin opens the plugin's logs.
Affects versions up to 27.7. Update to 28.0, then check the log.
https://suriq.io/blog/bookly-unauthenticated-stored-xss-cve-2026-13424
2026-08-16T08:44:14.263Z