Executive brief
The Astro Booking Engine is a WordPress plugin that manages booking functionality for websites. An unauthenticated attacker can trick a site administrator into clicking a malicious link to delete all plugin settings, disrupting booking operations and potentially exposing configuration information.
Technical details
This is a Cross-Site Request Forgery (CSRF) vulnerability in the Astro Booking Engine WordPress plugin affecting all versions up to 1.4.0. The vulnerability exists in the options deletion functionality, which lacks proper nonce validation to prevent forged requests. An attacker can craft a malicious request that, when clicked by an authenticated administrator, will delete all plugin settings without the administrator's knowledge. The attack requires social engineering (tricking an admin into clicking a link) but requires no authentication from the attacker's perspective. The fix involves adding proper nonce checks to the deletion functionality.
Affected products
- Astro Themes Astro Booking Engine up to and including 1.4.0
Timeline
- 2026-08-14: disclosed