
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68976 is a Missing Authorization vulnerability in the Eagle-Themes Eagle Booking WordPress plugin that allows authenticated attackers with low-level privileges (Subscriber-level) to perform unauthorized settings changes. It affects Eagle Booking versions up to and including 1.3.4.3. The vulnerability was reported on October 19, 2025, and published by Patchstack on November 18, 2025. It carries a CVSS v3.1 base score of 5.4 (Medium) (Patchstack).
The vulnerability is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether an authenticated user has the appropriate permissions before allowing access to sensitive administrative functions. An attacker with a low-privileged account (e.g., Subscriber role) can send crafted requests to plugin endpoints that handle settings changes without adequate authorization checks, effectively bypassing access control. The attack vector is network-based, requires no user interaction, and has low attack complexity, making it straightforward to exploit for any authenticated user (Patchstack).
Successful exploitation allows a low-privileged authenticated attacker to modify plugin configuration settings without authorization, potentially disrupting the booking system's availability and integrity. While the CVSS score reflects no direct confidentiality impact, unauthorized settings changes could be leveraged to alter booking workflows, redirect users, or degrade service availability. The scope is limited to the affected WordPress installation, but on shared hosting environments, disruption of the booking plugin could have downstream business impact (Patchstack).
There is no public proof-of-concept exploit available, and no evidence of active in-the-wild exploitation has been observed. The EPSS score is approximately 0.017%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack classifies this as low priority, noting it is unlikely to be exploited despite the potential for use in mass-exploit campaigns targeting WordPress plugins (Patchstack).
As of the time of disclosure, no official patched version of the Eagle Booking plugin is available. Site administrators should consider disabling or removing the plugin until a security update is released. As interim mitigations, restrict user registration and limit Subscriber-level accounts on the WordPress site, and implement a web application firewall (WAF) rule to block unauthorized access to plugin settings endpoints. Monitor WordPress admin logs for unexpected settings changes originating from low-privileged accounts (Patchstack).
The vulnerability was noted by security aggregators including VulDB and briefly mentioned on social media platforms such as Mastodon and Bluesky by TheHackerWire. Community sentiment reflects low concern given the medium severity score, absence of a public exploit, and the niche user base of the Eagle Booking plugin. Patchstack, the assigning CNA, categorized it as low priority with no impactful threat at the time of publication (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."