CVE-2025-4691

medium

Description

The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.21 via the 'view_request_details' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view the details of any booking request. The vulnerability was partially patched in versions 1.3.18 and 1.3.21.

References

https://www.wordfence.com/threat-intel/vulnerabilities/id/3c9953b3-dd09-4c80-be11-4daf3bbac720?source=cve

https://plugins.trac.wordpress.org/changeset/3300408/

https://plugins.trac.wordpress.org/changeset/3293607/

https://plugins.trac.wordpress.org/changeset/3243634/

https://plugins.trac.wordpress.org/browser/easync-booking/tags/1.3.17/easync.php#L4859

Details

Source: Mitre, NVD

Published: 2025-05-31

Updated: 2025-06-02

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Severity: Medium

EPSS

EPSS: 0.00022