stellarwp Vulnerabilities and Affected Products
Vulnerabilities associated with Bookit — Booking & Appointment Calendar.
Products
Clear product- GiveWP – Donation Plugin and Fundraising Platform31 vulnerabilities
- Kadence Blocks — Page Builder Toolkit for Gutenberg Editor29 vulnerabilities
- The Events Calendar19 vulnerabilities
- GiveWP10 vulnerabilities
- Membership Plugin – Restrict Content7 vulnerabilities
- Event Tickets and Registration6 vulnerabilities
- LearnDash LMS5 vulnerabilities
- Bookit — Booking & Appointment Calendar3 vulnerabilities
- Event Tickets3 vulnerabilities
- Gutenberg Blocks by Kadence Blocks3 vulnerabilities
- Kadence WooCommerce Email Designer3 vulnerabilities
- WPComplete3 vulnerabilities
- Restrict Content2 vulnerabilities
- Give – Divi Donation Modules1 vulnerability
- Image Widget1 vulnerability
- iThemes Sync1 vulnerability
- LearnDash LMS – Reports1 vulnerability
- Membership Plugin – Kadence Memberships1 vulnerability
- the_events_calendar1 vulnerability
- Virtue1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-12633HIGH | Booking Calendar | Appointment Booking | Bookit <= 2.5.0 - Missing Authorization to Unauthenticated Stripe ConnectionThe Booking Calendar | Appointment Booking | Bookit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/wp-json/bookit/v1/commerce/stripe/return' REST API Endpoint in all versions up to, and including, 2.5.0. This makes it possible for unauthenticated attackers to connect their Stripe account and receive payments. CWE-862Nov 12, 2025 | CVSS7.5v3.1 | EPSS0.257% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-4974MEDIUM | Freemius SDK <= 2.4.2 - Missing Authorization ChecksThe Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable. CWE-862Oct 16, 2024 | CVSS6.3v3.1 | EPSS0.442% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-2834CRITICAL | BookIt <= 2.3.7 - Authentication BypassThe BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is due to insufficient verification on the user being supplied during booking an appointment through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email. | CVSS9.8v3.1 | EPSS1.91% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |