Executive brief
Eagle Booking is a WordPress plugin used by hotels and accommodation providers to manage reservations and bookings. A security flaw allows an attacker to trick a website administrator into performing unintended actions, such as changing settings or deleting data, by getting them to click a malicious link. This could lead to a full takeover of the booking system or unauthorized changes to customer reservations.
Technical details
The Eagle Booking plugin for WordPress (versions <= 1.3.4.3) fails to implement proper nonce validation or CSRF protections on sensitive administrative functions. An unauthenticated remote attacker can exploit this by crafting a malicious web page or link and tricking a logged-in administrator into visiting it. Because the application does not verify the intent of the request, the attacker can execute arbitrary actions with the privileges of the victim, potentially leading to unauthorized configuration changes or data manipulation. As of the advisory date, no official patch has been released.
Affected products
- Eagle-Themes Eagle Booking <= 1.3.4.3
Timeline
- 2025-10-19: disclosed: Vulnerability reported by researcher Bonds
- 2026-06-26: advisory: Public advisory published by Patchstack