CVE-2025-10308: Astro Booking Engine <= 1.4.0 - Cross-Site Request Forgery to Settings Reset
The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing nonce validation on the options deletion functionality. This makes it possible for unauthenticated attackers to delete all plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Astro Booking Engineto a version that resolves this vulnerability.Fixed in 1.4.0 - Compensating control
Ensure only authenticated administrators can access the Astro Booking Engine options deletion functionality and block CSRF-prone links (e.g., via strict browser/anti-CSRF measures) until the missing nonce validation is fixed.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10308?
The severity of CVE-2025-10308 is medium with a CVSS score of 4.3.
What does CVE-2025-10308 affect?
CVE-2025-10308 affects the Astro Booking Engine plugin for WordPress in all versions up to and including 1.4.0.
What type of vulnerability is CVE-2025-10308?
CVE-2025-10308 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2025-10308?
To fix CVE-2025-10308, upgrade the Astro Booking Engine plugin to the latest version that includes nonce validation.
What can attackers do with CVE-2025-10308?
With CVE-2025-10308, unauthenticated attackers can delete all settings of the Astro Booking Engine plugin.