CVE-2025-12841: Unknown Bookit

Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.

The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST endpoint that allows unauthenticated update of the plugins Stripe payment options.

Affected products

  • Unknown Bookit: before 2.5.1 (fixed in 2.5.1)

Published 2025-12-12. Last modified 2026-10-07.