Medium severity5.3NVD Advisory· Published Dec 12, 2025· Updated Apr 15, 2026
CVE-2025-12841
CVE-2025-12841
Description
The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST endpoint that allows unauthenticated update of the plugins Stripe payment options.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.