Unauthorized Data Access in Booking X Plugin for WordPress
CVE-2025-6814
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 4 July 2025
What is CVE-2025-6814?
The Booking X plugin for WordPress has a critical flaw that allows unauthorized users to access sensitive data. This issue arises from the lack of a capability check in the export_now() function. Versions 1.0 through 1.1.2 are affected, enabling unauthenticated attackers to craft POST requests and download confidential information, including user accounts and PayPal credentials. It is essential for users and administrators to update the plugin to mitigate this risk and strengthen their site's security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Booking X β Appointment and Reservation Availability Calendar 1.0 <= 1.1.2
References
CVSS V3.1
Timeline
Vulnerability published