CVE-2025-10124
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/10/2025
Last modified:
13/11/2025
Description
The Booking Manager WordPress plugin before 2.1.15 registers a shortcode that deletes bookings and makes that shortcode available to anyone with contributor and above privileges. When a page containing the shortcode is visited, the bookings are deleted.
Impact
Base Score 3.x
4.50
Severity 3.x
MEDIUM



