CVE-2025-10124: Unknown Booking Manager
Medium severity, CVSS 4.5. EPSS: 0.3% chance of exploitation in the next 30 days.
The Booking Manager WordPress plugin before 2.1.15 registers a shortcode that deletes bookings and makes that shortcode available to anyone with contributor and above privileges. When a page containing the shortcode is visited, the bookings are deleted.
Affected products
- Unknown Booking Manager: before 2.1.15 (fixed in 2.1.15)
Published 2025-10-10. Last modified 2026-10-08.