What is CVE-2025-10308?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Astro Booking Engine plugin for WordPress up to version 1.4.0 due to missing nonce validation. This flaw allows unauthenticated attackers to delete all plugin settings via crafted requests. Users should update the plugin to a patched version as soon as possible.
Azərbaycanca: WordPress üçün Astro Booking Engine plaginin 1.4.0 və əvvəlki versiyalarında Cross-Site Request Forgery (CSRF) zəifliyi aşkarlanıb. Bu zəiflik nonce yoxlamasının olmaması səbəbindən autentifikasiya olunmamış hücumçulara plagin parametrlərini silməyə imkan verir. İstifadəçilərə plaqini ən son təhlükəsiz versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
Which versions of the Astro Booking Engine plugin are affected by CVE-2025-10308?
This Cross-Site Request Forgery (CSRF) vulnerability exists in the Astro Booking Engine plugin for WordPress up to and including version 1.4.0.
What can an unauthenticated attacker achieve by exploiting this CSRF vulnerability?
Due to missing nonce validation, unauthenticated attackers can delete all plugin settings via crafted requests.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.