Showing 3 vulnerabilities on this page for Bookit — Booking & Appointment Calendar

Signals CISA KEV Ransomware Nuclei
stellarwp vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Booking Calendar | Appointment Booking | Bookit <= 2.5.0 - Missing Authorization to Unauthenticated Stripe Connection

The Booking Calendar | Appointment Booking | Bookit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/wp-json/bookit/v1/commerce/stripe/return' REST API Endpoint in all versions up to, and including, 2.5.0. This makes it possible for unauthenticated attackers to connect their Stripe account and receive payments.

CWE-862Nov 12, 2025
CVSS7.5v3.1EPSS0.257%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Freemius SDK <= 2.4.2 - Missing Authorization Checks

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.

CWE-862Oct 16, 2024
CVSS6.3v3.1EPSS0.442%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

BookIt <= 2.3.7 - Authentication Bypass

The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is due to insufficient verification on the user being supplied during booking an appointment through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

CWE-288CWE-306Jun 30, 2023
CVSS9.8v3.1EPSS1.91%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX