CVE-2025-4691 Details
Description
The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.21 via the 'view_request_details' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view the details of any booking request. The vulnerability was partially patched in versions 1.3.18 and 1.3.21.
A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the Free Booking Plugin for Hotels, Restaurants and Car Rentals - eaSYNC Booking, affecting all versions through 1.3.21. The vulnerability arises from inadequate validation of user-controlled input in the 'view_request_details' feature, enabling unauthenticated attackers to access details of any booking request. Although this issue was partially addressed in versions 1.3.18 and 1.3.21, the vulnerability still exists in the 1.3.21 version.
Users are advised to update the plugin to version 1.3.22 or a newer patched version.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 2, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| syntacticsinc easync | < 1.3.22 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 23, 2026 | CPE Deprecation Remap | [email protected] |
| Jul 10, 2025 | Initial Analysis | [email protected] |
| May 31, 2025 | New CVE Received | [email protected] |