Astro Booking Engine
Astro Booking Engine has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Astro Booking Engine has a vendor fix available, so running the current release closes it.
All of these findings were reported by Nabil Irawan. Astro Booking Engine is installed on roughly 20 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-10308Astro Booking Engine <= 1.4.0 - Cross-Site Request Forgery to Settings Reset
Read the full analysisVulnerability Records

Astro Booking Engine
Author
Alian Schiavoncini
Display the booking engine form through the use of the shortcode [astro-booking-engine]. Includes the most popular booking engine providers. You need to have a contract with one of the booking engine providers listed below and configure the plugin settings. List of configurable booking engine providers in alphabetical order: 5Stelle Iperbooking Passepartout Simple booking Vertical booking New booking engine providers are welcome! If your booking engine provider is not on the list, you can request its inclusion by sending an email to alian@alian.it with the provider documentation if you have. This plugin is compatible with translation plugins such as WPML and Loco Translate. Wordefence vendor verification key gsphudo7by90lzwdlihyerqxbzj6jiln
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C