plugin

Astro Booking Engine Vulnerabilities

1 known security issue reported for the Astro Booking Engine WordPress plugin. Most recent disclosed Aug 13, 2026.

1 medium

Running Astro Booking Engine on your site? Check whether your installed version is affected.

Scan your site free

Astro Booking Engine <= 1.4.0 - Cross-Site Request Forgery to Settings Reset

medium

The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing nonce validation on the options deletion functionality. This makes it possible for unauthenticated attackers to delete all plugin settings via a forged request gr...

CVSS:
4.3
Affected:
up to 1.4.0
Fixed in:
1.4.1
Disclosed:
Aug 13, 2026

CVE-2025-10308 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database