CVE-2025-12841: Unknown Bookit
Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.
The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST endpoint that allows unauthenticated update of the plugins Stripe payment options.
Affected products
- Unknown Bookit: before 2.5.1 (fixed in 2.5.1)
Published 2025-12-12. Last modified 2026-10-07.