cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches foreasync-booking easync-booking

Direction: ascending
Jun 07, 2024

Free Booking Plugin for Hotels, Restaurant and Car Rental – eaSYNC # CVE-2022-1952

CVE, Research URL

CVE-2022-1952

Date
Jul 11, 2022
Research Description
The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient input validation which leads to arbitrary file upload and subsequently to remote code execution. An AJAX action accessible to unauthenticated users is affected by this issue. An allowlist of valid file extensions is defined but is not used during the validation steps.
Affected versions
Min -, max -.
Status
vulnerable

Free Booking Plugin for Hotels, Restaurant and Car Rental – eaSYNC # CVE-2023-38384

CVE, Research URL

CVE-2023-38384

Date
Aug 08, 2023
Research Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Syntactics, Inc. EaSYNC plugin <= 1.3.7 versions.
Affected versions
Min -, max -.
Status
vulnerable

Free Booking Plugin for Hotels, Restaurant and Car Rental &#8211; eaSYNC # 303b11b3f720ed67e3d2bfcb065436e505f26d37

Date
Feb 28, 2022
Research Description
Free Booking Plugin for Hotels, Restaurants and Car Rentals &#8211; eaSYNC Booking [easync-booking] < 1.1.10 WordPress Free Booking Plugin for Hotels, Restaurant and Car Rental – eaSYNC plugin <= 1.1.9 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Free Booking Plugin for Hotels, Restaurant and Car Rental – eaSYNC plugin (versions <= 1.1.9).
Affected versions
Min -, max -.
Status
vulnerable
Nov 16, 2024

Free Booking Plugin for Hotels, Restaurant and Car Rental &#8211; eaSYNC # CVE-2022-4974

CVE, Research URL

CVE-2022-4974

Date
Oct 16, 2024
Research Description
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Affected versions
Min -, max -.
Status
vulnerable
Apr 06, 2025

Free Booking Plugin for Hotels, Restaurant and Car Rental &#8211; eaSYNC # CVE-2025-32219

CVE, Research URL

CVE-2025-32219

Date
Apr 04, 2025
Research Description
Missing Authorization vulnerability in Syntactics, Inc. eaSYNC allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects eaSYNC: from n/a through 1.3.19.
Affected versions
Min -, max -.
Status
vulnerable