CVE-2025-4691: Syntacticsinc Easync
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.21 via the 'view_request_details' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view the details of any booking request. The vulnerability was partially patched in versions 1.3.18 and 1.3.21.
Affected products
- Syntacticsinc Easync: before 1.3.22 (fixed in 1.3.22)
Published 2025-05-31. Last modified 2026-06-17.