CVE-2025-62916
8.8Adivaha · Flights & Hotels Booking WP Plugin
A missing authorization vulnerability in the Adivaha Flights & Hotels Booking WP Plugin allows authenticated users to exploit incorrectly configured access controls.
Executive summary
A missing authorization vulnerability in the Adivaha Flights & Hotels Booking WP Plugin allows authenticated users to bypass security controls, posing a risk of unauthorized data manipulation.
Vulnerability
The plugin suffers from a missing authorization flaw (CWE-862) that permits an authenticated user with low privileges to perform actions due to incorrectly configured access control security levels.
Business impact
The exploitation of this vulnerability could lead to unauthorized modifications or service disruption within the booking platform. Given the CVSS score of 8.8, this is a high-severity issue that could compromise the integrity of business operations and customer data if left unmitigated.
Remediation
Immediate Action: As no specific patch version is currently identified, administrators should monitor the official WordPress plugin repository for security updates and apply them as soon as they are released.
Proactive Monitoring: Review web server and application access logs for unusual patterns of activity originating from low-privileged user accounts, specifically targeting booking management endpoints.
Compensating Controls: Implement a Web Application Firewall (WAF) rule to restrict unauthorized access to plugin-specific AJAX actions or administrative endpoints until a vendor-supplied patch is available.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations utilizing this plugin must prioritize this vulnerability due to its high CVSS score. While the requirement for authentication reduces the attack surface, the potential for unauthorized access remains a significant risk; therefore, immediate action should be taken to update the plugin once a fix is published by the vendor.
Sources
Originally found and disclosed by Legion Hunter | Patchstack Bug Bounty Program, per the CVE Program record.