CVE-2025-68976

8.8

Eagle-Themes · Eagle Booking

A missing authorization vulnerability in the Eagle Booking WordPress plugin allows authenticated users to exploit improperly configured access control settings.

Executive summary

A missing authorization flaw in the Eagle Booking plugin for WordPress allows authenticated users to bypass access controls, potentially leading to unauthorized configuration changes.

Vulnerability

This vulnerability is caused by a missing authorization check, which allows a low-privileged authenticated user to interact with administrative settings or functions that should be restricted. The flaw is identified as CWE-862 and requires the attacker to have at least low-level authenticated access to the application.

Business impact

The ability for unauthorized users to modify plugin settings poses a significant risk to the integrity and availability of the booking system. An attacker could alter critical configurations, disrupt reservation workflows, or perform actions that impact business operations, justifying the high CVSS score of 8.8 despite the authentication requirement.

Remediation

Immediate Action: Review the official Patchstack advisory for updates and monitor the Eagle-Themes vendor site for a patched version release beyond 1.3.4.3.

Proactive Monitoring: Audit WordPress user activity logs for unauthorized access to plugin settings pages or unexpected changes to booking configurations.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious requests targeting plugin administrative endpoints.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for unauthorized configuration changes, administrators should treat this vulnerability with high priority. We recommend restricting access to administrative functions and monitoring the plugin vendor closely for the release of a security update that addresses the authorization deficiency.

More Eagle-Themes CVEs

Sources

Originally found and disclosed by Bonds | Patchstack Bug Bounty Program, per the CVE Program record.