Unauthorized Email Sending in Booking Plugin for WordPress from Vendor WordPress
CVE-2025-12842
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 November 2025
What is CVE-2025-12842?
The Booking Plugin for WordPress Appointments - Time Slot is impacted by a vulnerability that allows unauthenticated users to send emails through the tslot_appt_email AJAX action without proper validation. This flaw can lead to unauthorized sending of appointment notification emails, allowing malicious actors to leverage the plugin for phishing attacks or spam distribution. It is critical for users of versions up to 1.4.7 to update their installations to mitigate the risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Booking Plugin for WordPress Appointments β Time Slot * <= 1.4.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved