
Cloud Vulnerability DB
A community-led vulnerabilities database
The Booking Manager plugin versions before 2.1.15 contains a vulnerability that allows users with contributor and above privileges to delete bookings through an improperly secured shortcode. The vulnerability was discovered by Khaled Alenazi (Nxploited) and was publicly disclosed on September 19, 2025, with CVE identifier CVE-2025-10124. The vulnerability affects the booking-manager WordPress plugin (WPScan).
The vulnerability is classified as an Incorrect Authorization issue (CWE-863) with a CVSS score of 4.5 (medium). The vulnerability occurs because the plugin registers a shortcode that deletes bookings and makes that shortcode available to users with contributor and above privileges. When a page containing the shortcode is visited, the bookings are deleted without proper authorization checks (WPScan).
When exploited, this vulnerability allows users with contributor-level access to delete any booking in the system by simply adding a malicious shortcode to a post or page. The deletion occurs when any user, including unauthenticated visitors, accesses the page containing the shortcode (WPScan).
The vulnerability has been fixed in version 2.1.15 of the Booking Manager plugin. Users are advised to update to this version or later to mitigate the risk. No alternative workarounds have been provided (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."