The Booking Manager WordPress plugin before 2.1.15 registers a shortcode that deletes bookings and makes that shortcode available to anyone with contributor and above privileges. When a page containing the shortcode is visited, the bookings are deleted.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 10 Oct 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Booking Manager WordPress plugin before 2.1.15 registers a shortcode that deletes bookings and makes that shortcode available to anyone with contributor and above privileges. When a page containing the shortcode is visited, the bookings are deleted. | |
Title | Booking Manager < 2.1.15 - Contributor+ Booking Deletion | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-10-10T06:00:06.988Z
Reserved: 2025-09-08T17:28:36.714Z
Link: CVE-2025-10124

No data.

Status : Received
Published: 2025-10-10T06:15:32.217
Modified: 2025-10-10T06:15:32.217
Link: CVE-2025-10124

No data.

No data.