---
id: CVE-2025-12841
title: >-
  The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST
  endpoint that allows unauthenticated update of the plugins Stripe payment
  options.
summary: >-
  The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST
  endpoint that allows unauthenticated update of the plugins Stripe payment
  options.
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
published: '2025-12-12'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12841'
references:
  - url: 'https://wpscan.com/vulnerability/60cb3d5f-1aa5-4858-ab84-07fe7c023fdd/'
    label: contact@wpscan.com
tags:
  - nvd
  - exploit-available
epss: 0.00704
epssPercentile: 0.51769
exploits:
  nuclei:
    - CVE-2025-12841
  checkedAt: '2026-10-07T20:47:22.829Z'
exploitAvailable: true
ingestedAt: '2026-10-07T20:46:46.900Z'
---

## Overview

The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST endpoint that allows unauthenticated update of the plugins Stripe payment options.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
