A vulnerability classified as problematic was found in magepeopleteam WpBookingly Plugin up to 1.3.2 on WordPress. Impacted is an unknown function. The manipulation results in cross site scripting. This vulnerability is reported as CVE-2026-66687 . The attack can be launched remotely. No exploit exists.