tag
Cookie-Injection
Critical
Form Notify WordPress Plugin — LINE OAuth Authentication Bypass to Account Takeover (CVE-2026-5229)
CVE-2026-5229·
Form Notify WordPress plugin, LINE Login OAuth 2.0 integration (src/APIs/Line/Login/Route.php, User.php)
patched
High
Bookly Booking Form Cookie-Based Stored XSS — CVE-2026-5513
CVE-2026-5513·
Bookly — Online Scheduling and Appointment Booking System (WordPress plugin)
patched