CVE-2025-12573: Unknown Bookingor
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
The Bookingor WordPress plugin through 1.0.12 exposes authenticated AJAX actions without capability or nonce checks, allowing low-privileged users to delete Bookingor WordPress plugin through 1.0.12 data.
Affected products
- Unknown Bookingor: up to and including 1.0.12
Published 2026-01-20. Last modified 2026-06-17.