Record summary

CVE-2025-12633 has a selected CVSS score of 7.5 (high).

Description

The Booking Calendar | Appointment Booking | Bookit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/wp-json/bookit/v1/commerce/stripe/return' REST API Endpoint in all versions up to, and including, 2.5.0. This makes it possible for unauthenticated attackers to connect their Stripe account and receive payments.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 12, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Bookit — Booking & Appointment Calendar

Browse stellarwp / Bookit — Booking & Appointment Calendar

Default status: unaffected

CVE ListThrough 2.5.0affected

References

3