cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches foreasync-booking easync-booking

Direction: descending
Jun 04, 2025

Free Booking Plugin for Hotels, Restaurant and Car Rental – eaSYNC # CVE-2025-4691

CVE, Research URL

CVE-2025-4691

Date
May 31, 2025
Research Description
The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.21 via the 'view_request_details' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view the details of any booking request. The vulnerability was partially patched in versions 1.3.18 and 1.3.21.
Affected versions
max 1.3.22.
Status
vulnerable
May 19, 2025

Free Booking Plugin for Hotels, Restaurant and Car Rental – eaSYNC # CVE-2024-9450

CVE, Research URL

CVE-2024-9450

Date
May 16, 2025
Research Description
The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in subscriber change them via a CSRF attack
Affected versions
max 1.3.15.
Status
vulnerable
Apr 06, 2025

Free Booking Plugin for Hotels, Restaurant and Car Rental – eaSYNC # CVE-2025-32219

CVE, Research URL

CVE-2025-32219

Date
Apr 04, 2025
Research Description
Missing Authorization vulnerability in Syntactics, Inc. eaSYNC allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects eaSYNC: from n/a through 1.3.19.
Affected versions
max 1.3.19.
Status
vulnerable
Nov 16, 2024

Free Booking Plugin for Hotels, Restaurant and Car Rental – eaSYNC # CVE-2022-4974

CVE, Research URL

CVE-2022-4974

Date
Oct 16, 2024
Research Description
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Affected versions
max 1.1.10.
Status
vulnerable
Jun 07, 2024

Free Booking Plugin for Hotels, Restaurant and Car Rental – eaSYNC # CVE-2022-1952

CVE, Research URL

CVE-2022-1952

Date
Jul 11, 2022
Research Description
The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient input validation which leads to arbitrary file upload and subsequently to remote code execution. An AJAX action accessible to unauthenticated users is affected by this issue. An allowlist of valid file extensions is defined but is not used during the validation steps.
Affected versions
max 1.1.10.
Status
vulnerable

Free Booking Plugin for Hotels, Restaurant and Car Rental – eaSYNC # CVE-2023-38384

CVE, Research URL

CVE-2023-38384

Date
Aug 08, 2023
Research Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Syntactics, Inc. EaSYNC plugin <= 1.3.7 versions.
Affected versions
max 1.3.7.
Status
vulnerable

Free Booking Plugin for Hotels, Restaurant and Car Rental &#8211; eaSYNC # 303b11b3f720ed67e3d2bfcb065436e505f26d37

Date
Feb 28, 2022
Research Description
Free Booking Plugin for Hotels, Restaurants and Car Rentals &#8211; eaSYNC Booking [easync-booking] < 1.1.10 WordPress Free Booking Plugin for Hotels, Restaurant and Car Rental – eaSYNC plugin <= 1.1.9 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Free Booking Plugin for Hotels, Restaurant and Car Rental – eaSYNC plugin (versions <= 1.1.9).
Affected versions
max 1.1.10.
Status
vulnerable