Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16555 | The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.21 via the 'view_request_details' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view the details of any booking request. The vulnerability was partially patched in versions 1.3.18 and 1.3.21. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 10 Jul 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Syntactics
Syntactics free Booking Plugin For Hotels\, Restaurant And Car Rental |
|
| CPEs | cpe:2.3:a:syntactics:free_booking_plugin_for_hotels\,_restaurant_and_car_rental:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Syntactics
Syntactics free Booking Plugin For Hotels\, Restaurant And Car Rental |
Mon, 02 Jun 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 31 May 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.21 via the 'view_request_details' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view the details of any booking request. The vulnerability was partially patched in versions 1.3.18 and 1.3.21. | |
| Title | Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking <= 1.3.21 - Insecure Direct Object Reference to Sensitive Information Exposure | |
| Weaknesses | CWE-639 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-06-02T15:48:20.006Z
Reserved: 2025-05-14T15:45:37.633Z
Link: CVE-2025-4691
Updated: 2025-06-02T15:17:00.510Z
Status : Analyzed
Published: 2025-05-31T12:15:20.133
Modified: 2025-07-10T14:19:42.337
Link: CVE-2025-4691
No data.
OpenCVE Enrichment
No data.
EUVD