5.3

CVE-2025-4691

Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking <= 1.3.21 - Insecure Direct Object Reference to Sensitive Information Exposure

Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking <= 1.3.21 - Insecure Direct Object Reference to Sensitive Information Exposure

The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.21 via the 'view_request_details' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view the details of any booking request. The vulnerability was partially patched in versions 1.3.18 and 1.3.21.
Mögliche Gegenmaßnahme
eaSYNC Booking – Hotels, Restaurants & Car Rentals: Update to version 1.3.22, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SyntacticsincEasync SwPlatformwordpress Version < 1.3.22
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt eaSYNC Booking – Hotels, Restaurants & Car Rentals
Version *-1.3.21
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.194
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@wordfence.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-639 Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

https://www.wordfence.com/threat-intel/vulnerabilities/id/3c9953b3-dd09-4c80-be11-4daf3bbac720?source=cve
Third Party Advisory
https://plugins.trac.wordpress.org/browser/easync-booking/tags/1.3.17/easync.php#L4859
Product
https://plugins.trac.wordpress.org/changeset/3243634/
Patch
https://plugins.trac.wordpress.org/changeset/3293607/
Patch
https://plugins.trac.wordpress.org/changeset/3300408/
Patch
https://www.wordfence.com/threat-intel/vulnerabilities/id/3c9953b3-dd09-4c80-be11-4daf3bbac720
Third Party Advisory