Bookly #1 WordPress Booking Plugin Lite before 14.5 has XSS via a jQuery.ajax request to ng-payment_details_dialog.js.
https://www.gubello.me/blog/bookly-blind-stored-xss/
https://wordpress.org/plugins/bookly-responsive-appointment-booking-tool/#developers