VYPR
Medium severity4.5NVD Advisory· Published Oct 10, 2025· Updated Apr 15, 2026

CVE-2025-10124

CVE-2025-10124

Description

The Booking Manager WordPress plugin before 2.1.15 registers a shortcode that deletes bookings and makes that shortcode available to anyone with contributor and above privileges. When a page containing the shortcode is visited, the bookings are deleted.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The Booking Manager WordPress plugin before 2.1.15 allows contributors and above to delete all bookings via a shortcode, leading to data loss.

The Booking Manager WordPress plugin before version 2.1.15 suffers from an incorrect authorization vulnerability. The plugin registers a shortcode that is intended to delete bookings, but it fails to properly restrict access to this functionality. As a result, the shortcode is made available to any user with contributor-level privileges or higher [1].

To exploit this vulnerability, an attacker with contributor or higher access to a WordPress site can embed the shortcode into a page or post. When any visitor (including the attacker themselves) loads that page, the shortcode executes and deletes all bookings managed by the plugin. No additional authentication or special permissions are required beyond the contributor role [1].

The impact of successful exploitation is the complete deletion of all booking data stored by the plugin. This can lead to significant data loss, disruption of business operations, and potential financial harm for sites that rely on the Booking Manager for reservations or appointments [1].

The vulnerability has been fixed in version 2.1.15 of the plugin. Users are strongly advised to update to this patched version immediately. The issue was discovered and reported by researcher Khaled Alenazi (Nxploited) [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.