Impact
The Astro Booking Engine plugin for WordPress is vulnerable to Cross‑Site Request Forgery because it fails to validate a nonce when deleting settings. This flaw creates the opportunity for an unauthenticated attacker to force a site administrator to execute a request that removes all plugin configuration. The consequence is the loss of all plugin configuration. The weakness is classified as CWE‑352.
Affected Systems
WordPress sites running the Astro Booking Engine plugin version 1.4.0 or earlier are affected. The vulnerability applies to all releases up to and including 1.4.0, regardless of the WordPress core version. Specific version details beyond <=1.4.0 are not provided.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, but the exploit is trivial since it requires no authentication and only social engineering to trick an admin into clicking a crafted link. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalogue. Based on the lack of authentication requirement, the likely attack vector is a phishing or malicious link presented to a site administrator, which when followed, triggers the deletion action. Given the low technical barrier, the risk remains present until mitigated.
OpenCVE Enrichment