=== Astro Booking Engine === Contributors: alian Tags: booking engine, hotel booking, hotel widget, hotel booking engine, booking widget Requires at least: 6.0.1 Tested up to: 7.1 Stable tag: 1.5.0 Requires PHP: 7.4 License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html Use shortcode [astro-booking-engine] to display the booking form of 5Stelle, Ericsoft, Iperbooking, MyGuestCare, Passepartout and other providers. == Description == Display the booking engine form through the use of the shortcode [astro-booking-engine]. Includes the most popular booking engine providers. You need to have a contract with one of the booking engine providers listed below and configure the plugin settings. List of configurable booking engine providers in alphabetical order: New booking engine providers are welcome! If your booking engine provider is not on the list, you can request its inclusion by sending an email to alian@alian.it with the provider documentation if you have. This plugin is compatible with translation plugins such as WPML and Loco Translate. == Installation == 1. Upload the entire `astro-booking-engine` folder to the `/wp-content/plugins/` directory. 1. Activate the plugin through the **Plugins** screen (**Plugins > Installed Plugins**). == Screenshots == 1. Frontend: booking engine form with calendar 2. Frontend: booking engine form with child age dropdown 3. Backend: settings - providers list 4. Backend: settings - provider config 5. Backend: layout customization == Wordefence vendor verification key == gsphudo7by90lzwdlihyerqxbzj6jiln == Changelog == = 1.5.0 = * Added: Ericsoft provider. * Added: MyGuestCare provider. * Fixed: on the settings screen some saved values were displayed wrong after saving: the Simple booking currency and the default and maximum numbers of adults and children for Simple booking and Vertical booking. * Compatibility: tested with WordPress 7.1. = 1.4.2 = * Compatibility: tested with WordPress 7.1. = 1.4.1 = * Security: fixed a Cross-Site Request Forgery issue in the "Remove all plugin settings" function (CVE-2025-10308). The action was performed on a plain GET request without nonce validation, so an administrator could be tricked into deleting all plugin settings by following a forged link. The request is now validated with a nonce and an explicit capability check. Thanks to Nabil Irawan (Heroes Cyber Security) for the responsible disclosure. * Fixed: on the Settings screen the shortcode name was showing the literal <strong> tags instead of being displayed in bold. * Changed: the plugin author is now Alian Schiavoncini (https://www.alian.it) and the support address is alian@alian.it. The previous AstroThemes website and email address are no longer active. * Changed: the admin menu is now named "Astro Plugins" instead of "AstroThemes". * Changed: the plugin version is now stored in the ASTRO_BE_VERSION constant instead of being read at runtime with get_plugin_data(). * Changed: the jQuery UI calendar stylesheet is now enqueued with a version number, so browsers pick up changes after an update. * Compatibility: tested with WordPress 7.0. = 1.4.0 = * Added: Wordefence vendor verification key. * Compatibility: tested with WordPress 6.8.3. = 1.3.0 = * Security: added security checks to the code. * Compatibility: tested with WordPress 6.6.1. = 1.2.0 = * Added: Passepartout provider. = 1.1.1 = * Changed: the plugin description. = 1.1.0 = * Added: 5Stelle provider. = 1.0.2 = * Added: Italian translation. = 1.0.1 = * Changed: the support link on the admin settings screen. = 1.0.0 = * Initial version. == Upgrade Notice == = 1.4.2 = Maintenance release: compatibility with WordPress 7.1. If you are updating from 1.4.0 or earlier it also includes the security fix for CVE-2025-10308, released in 1.4.1. = 1.4.1 = Security release. Fixes a CSRF issue (CVE-2025-10308) that allowed an administrator to be tricked into deleting all plugin settings through a forged link. Updating is recommended.