
CVE-2025-10308 The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing nonce va… https://www.cve.org/CVERecord?id=CVE-2025-10308
Post summary
CVE‑2025‑10308 exposes a CSRF flaw in the Astro Booking Engine WordPress plugin (versions ≤1.4.0) caused by a missing nonce, with no PoC, exploit, patch or active exploitation reports mentioned.
