HomeDefault status
unaffected
Any version before 2.5.1
affected
Description
The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST endpoint that allows unauthenticated update of the plugins Stripe payment options.
Problem types
Product status
Any version before 2.5.1
Credits
Khaled Alenazi (Nxploited)
WPScan
References
wpscan.com/...rability/60cb3d5f-1aa5-4858-ab84-07fe7c023fdd/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.