6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Description
The Bookingor WordPress plugin through 1.0.12 exposes authenticated AJAX actions without capability or nonce checks, allowing low-privileged users to delete Bookingor WordPress plugin through 1.0.12 data.
Basic Information
ID
CVE-2025-12573
Source
WPScan
Published
Jan 20, 2026 at 06:00
Modified
Jan 20, 2026 at 14:31
Affected Product
Vendor
Unknown
Product
Bookingor
Affected Versions
Unknown Bookingor 0