CVE-2025-10124: Booking Manager < 2.1.15 - Contributor+ Booking Deletion
Published Oct 10, 2025
·Updated
The Booking Manager WordPress plugin before 2.1.15 registers a shortcode that deletes bookings and makes that shortcode available to anyone with contributor and above privileges. When a page containing the shortcode is visited, the bookings are deleted.
Affected Software
1 affected component
Booking Manager Booking Manager<2.1.15
Event History
Oct 10, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverity
Jul 14, 57839
Event
via NVD·08:22 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-10124?
The severity of CVE-2025-10124 is considered high due to the ability of unauthorized users to delete bookings.
2
How do I fix CVE-2025-10124?
To fix CVE-2025-10124, update the Booking Manager plugin to version 2.1.15 or higher.
3
What versions of the Booking Manager are affected by CVE-2025-10124?
CVE-2025-10124 affects versions of the Booking Manager plugin prior to 2.1.15.
4
Who can exploit CVE-2025-10124?
CVE-2025-10124 can be exploited by any user with contributor privileges or higher in WordPress.
5
What is the impact of CVE-2025-10124?
The impact of CVE-2025-10124 is that it allows unauthorized deletion of bookings through a registered shortcode.