← WordPress Vulnerabilities
WordPress security by component

Eagle Booking

Eagle Booking is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Jun 26, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: eagle-booking

CVE-2025-68052: Eagle Booking: Cross-site request forgery

Eagle Booking is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 1.3.4.3.

PublishedJun 26, 2026
Known safe version> 1.3.4.3
Safe version
Jun 26, 2026 CVE-2025-68052
Eagle Booking: Cross-site request forgery
Eagle Booking is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 1.3.4.3.
> 1.3.4.3
CVE8.8
NVDPending
Mar 05, 2026 CVE-2026-27428
Eagle Booking: SQL injection
Eagle Booking is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVDPending
Dec 30, 2025 CVE-2025-68976
Eagle Booking: A security weakness
Eagle Booking is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Dec 30, 2025 CVE-2025-68975
Eagle Booking: A security weakness
Eagle Booking is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending