Description
Authorization Bypass Through User-Controlled Key vulnerability in Eagle-Themes Eagle Booking eagle-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eagle Booking: from n/a through <= 1.3.4.3.
Published: 2025-12-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an insecure direct object reference that permits an attacker to supply a manipulated user‑controlled key, thereby bypassing the intended access control checks when accessing booking records in the Eagle Booking plugin. This flaw, identified as Authorization Bypass Through User‑Controlled Key (CWE-639), can expose or alter reservation information, compromising the confidentiality and integrity of booking data within the affected WordPress site.

Affected Systems

WordPress installations that utilize the Eagle-Themes Eagle Booking plugin version 1.3.4.3 or earlier are susceptible; administrators of any site running the legacy plugin should verify the current version and its installed state.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation in the present environment. The vulnerability is not listed in the CISA KEV catalog. Based on the plugin’s design, the attack vector is most likely a remote web request where an attacker supplies a crafted key to access or modify booking entries, and no special environmental prerequisites are noted in the description.

Generated by OpenCVE AI on April 29, 2026 at 22:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Eagle Booking plugin to the latest release that resolves the IDOR flaw.
  • If an immediate upgrade is not feasible, disable the plugin or remove it from the site to block exploitation.
  • Confirm that all booking‑object access points enforce proper authentication and authorization, ensuring only trusted users can reference booking identifiers.
  • Review other WordPress plugins and core functions for similar IDOR weaknesses and keep all components updated.

Generated by OpenCVE AI on April 29, 2026 at 22:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Tue, 30 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 30 Dec 2025 11:00:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key vulnerability in Eagle-Themes Eagle Booking eagle-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eagle Booking: from n/a through <= 1.3.4.3.
Title WordPress Eagle Booking plugin <= 1.3.4.3 - Insecure Direct Object References (IDOR) vulnerability
Weaknesses CWE-639
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:33.400Z

Reserved: 2025-12-29T11:17:52.921Z

Link: CVE-2025-68975

cve-icon Vulnrichment

Updated: 2025-12-30T21:51:37.683Z

cve-icon NVD

Status : Deferred

Published: 2025-12-30T11:15:56.017

Modified: 2026-04-27T19:16:38.440

Link: CVE-2025-68975

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T22:15:16Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key