rootpwn

medium · CVSS v3 3.8 · EPSS 0.00132

CVE-2026-92420

The Hydra Booking Appointment Scheduling & Booking Calendar WordPress plugin before version 1.2.2 suffers from an insecure direct object ref

Overview

The Hydra Booking Appointment Scheduling & Booking Calendar WordPress plugin before version 1.2.2 suffers from an insecure direct object reference vulnerability. This flaw arises from a lack of proper user ownership verification when handling booking modification and deletion requests. Consequently, authenticated users with booking-provider privileges can compromise the confidentiality and integrity of other providers' booking data.

Description

The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user before modifying or deleting it on two of its booking endpoints, allowing a booking-provider-level user to cancel and permanently delete other providers' bookings on the same site.

Impact

Authenticated malicious or compromised booking-provider accounts can unauthorizedly cancel and permanently delete booking records belonging to other service providers on the same WordPress instance. This leads to unauthorized data loss and potential disruption of business operations. The impact is restricted to data integrity and availability within the scope of the plugin's booking database.

Remediation

Update the Hydra Booking Appointment Scheduling & Booking Calendar plugin to version 1.2.2 or later where proper authorization checks on booking endpoints are implemented. If an update is immediately unavailable, temporarily restrict booking-provider level access or disable the affected scheduling endpoints. Conduct an audit of recent booking modifications and deletions to detect potential unauthorized activity.

Risk context

The vulnerability is rated as medium severity with a CVSS v3 score of 3.8, reflecting the requirement for authenticated access and a specific privilege level. The low EPSS score of 0.00132 indicates a currently low probability of active exploitation in the wild, but defenders should still apply standard patch management practices.

Affected products

  • Hydra Booking WordPress plugin

Scores

Severity
medium
CVSS v2
4.7
CVSS v3
3.8
CVSS v4
EPSS
0.00132

WordPress IDOR Authorization Plugin Data Loss Web Application

← All CVEs