S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated May 20, 2026

CVE-2025-12841 Scanner

CVE-2025-12841 Scanner - Unauthorized Admin Access vulnerability in WordPress Bookit

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.5k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-12841
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST endpoint that allows unauthenticated update of the plugins Stripe payment options.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Bookit
AFFECTED< 2.5.1SAFE ✓≥ 2.5.1
Updated Aug 22, 2026View on NVD →
Detail

Scanner checks for vulnerabilities in the WordPress Bookit plugin, widely utilized in managing bookings and appointments on WordPress sites. This plugin is commonly leveraged by businesses for scheduling functionalities, providing a comprehensive solution for managing and processing customer appointments. Given its integration with payment gateways, secure management of this plugin is critical to prevent unauthorized modifications. The exploitability of this plugin can have serious implications for the seamless operation of appointment-driven businesses. Admins are encouraged to constantly update the plugin to defend against potential vulnerabilities. Ensuring up-to-date versions can dramatically reduce exposure to known weaknesses.

The vulnerability stems from a broken access control flaw, allowing unauthenticated users to modify Stripe payment settings. This presents significant risks, as attackers can perform unauthorized actions without needing valid credentials. The issue primarily lies in a REST endpoint that is inadequately protected. Unauthenticated changes to financial settings can lead to fraudulent activities or halt services. Understanding the vulnerability can help administrators implement stronger access controls and prevention measures. Regular reviews of access control mechanisms are imperative for securing financial configurations.

The flaw is located in an external REST endpoint that bypasses authentication requirements, allowing unrestricted modifications. HTTP requests can exploit this vulnerability, altering Stripe configurations used for transaction processing. Endpoint mishandling clearances may leave financial settings vulnerable to intrusions. Adjustable parameters include user ID and access token settings, typically used for Stripe authentication. Attackers manipulating these can interfere with the payment processing workflow. Identifying and securing these entry points is essential to mitigating risks associated with unauthorized access.

Exploitation may lead to severe consequences, such as unauthorized financial transactions and compromised payment data. Attackers may control Stripe configurations, leading to the redirection of payments or disruption in service offerings. Financial fraud potential increases as adversaries can reroute funds to unauthorized entities. Service interruptions may result from altered payment settings, affecting customer experiences adversely. Additionally, reputational damage and trust loss can occur due to compromised customer data integrity. Preventive measures can forestall exploitation, safeguarding business operations and customer interactions.

REFERENCES

Solution Advice
  • Upgrade the WordPress Bookit plugin to version 2.5.1 or later to eliminate the unauthorized access vulnerability.
  • Implement additional access controls for sensitive endpoints to restrict unauthorized modifications.
  • Regularly review REST endpoints for security loopholes and enforce strict authentication measures.
  • Monitor transaction logs for any unusual Stripe activities indicating potential unauthorized changes.
  • Ensure regular security audits to detect and rectify vulnerabilities preemptively in your WordPress plugins.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.