PT-2026-95767 · WordPress · Hydra Booking
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin versions prior to 1.2.3
Description
Authenticated users with a host role can modify profile data of other hosts and reassign ownership of those records to themselves because the plugin fails to verify if the host record being modified belongs to the user making the request.
Recommendations
Update Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin to version 1.2.3 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hydra Booking