Security Advisory
CVE-2025-12841
5.3
MEDIUM
Vulnerability Description
The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST endpoint that allows unauthenticated update of the plugins Stripe payment options.
Published Date
December 12, 2025
Official Source
NIST NVD Advisory