Security Advisory

CVE-2025-12841

5.3
MEDIUM

Vulnerability Description

The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST endpoint that allows unauthenticated update of the plugins Stripe payment options.
Published Date December 12, 2025
Official Source NIST NVD Advisory