Extension WordPress
Vulnérabilités eaSYNC Booking – Hotels, Restaurants & Car Rentals
Cette page rassemble les failles publiées pour eaSYNC Booking – Hotels, Restaurants & Car Rentals, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de eaSYNC Booking – Hotels, Restaurants & Car Rentals
7 fiches
Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking <= 1.3.21 – Insecure Direct Object Reference to Sensitive Information Exposure
The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.21 via the 'view_request_details' due to missing validation…
*-1.3.21
1.3.22
30/05/2025
eaSYNC <= 1.3.19 – Missing Authorization
The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.3.19.…
*-1.3.19
1.3.21
04/04/2025
Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking <= 1.3.14 – Cross-Site Request Forgery
The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.14. This is due to missing or incorrect nonce…
*-1.3.14
1.3.15
02/03/2025
eaSYNC <= 1.3.11 – Reflected Cross-Site Scripting
The eaSYNC plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
*-1.3.11
1.3.12
20/07/2023
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
1.1.5-1.3.6
1.3.7
18/07/2023
Free Booking Plugin for Hotels, Restaurant and Car Rental – eaSYNC <= 1.1.15 – Arbitrary File Upload
The Free Booking Plugin for Hotels, Restaurant and Car Rental is vulnerable to arbitrary file uploads due to missing file type validation via the ~/easync.php file in versions up to, and including, 1.1.15. This makes it possible for…
*-1.1.15
1.1.16
13/06/2022
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 1.1.10)
1.1.10
04/03/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.