PT-2025-41504 · WordPress · Booking Manager

Khaled Alenazi

+1

·

Published

2025-10-10

·

Updated

2025-10-10

·

CVE-2025-10124

CVSS v3.1

4.5

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions The Booking Manager WordPress plugin versions prior to 2.1.15
Description The Booking Manager WordPress plugin has an issue where a shortcode capable of deleting bookings is registered and accessible to users with contributor privileges or higher. Visiting a page containing this shortcode results in the deletion of bookings.
Recommendations Update The Booking Manager WordPress plugin to version 2.1.15 or later.

Exploit

Fix

Related Identifiers

CVE-2025-10124

Affected Products

Booking Manager