5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Description
The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST endpoint that allows unauthenticated update of the plugins Stripe payment options.
Basic Information
ID
CVE-2025-12841
Source
WPScan
Published
Dec 12, 2025 at 10:17
Modified
Dec 12, 2025 at 17:50
Affected Product
Vendor
Unknown
Product
Bookit
Affected Versions
Unknown Bookit 0