medium · CVSS v3 3.8 · EPSS 0.00132
CVE-2026-92420
The Hydra Booking Appointment Scheduling & Booking Calendar WordPress plugin before version 1.2.2 suffers from an insecure direct object ref
Overview
The Hydra Booking Appointment Scheduling & Booking Calendar WordPress plugin before version 1.2.2 suffers from an insecure direct object reference vulnerability. This flaw arises from a lack of proper user ownership verification when handling booking modification and deletion requests. Consequently, authenticated users with booking-provider privileges can compromise the confidentiality and integrity of other providers' booking data.
Description
The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user before modifying or deleting it on two of its booking endpoints, allowing a booking-provider-level user to cancel and permanently delete other providers' bookings on the same site.
Impact
Authenticated malicious or compromised booking-provider accounts can unauthorizedly cancel and permanently delete booking records belonging to other service providers on the same WordPress instance. This leads to unauthorized data loss and potential disruption of business operations. The impact is restricted to data integrity and availability within the scope of the plugin's booking database.
Remediation
Update the Hydra Booking Appointment Scheduling & Booking Calendar plugin to version 1.2.2 or later where proper authorization checks on booking endpoints are implemented. If an update is immediately unavailable, temporarily restrict booking-provider level access or disable the affected scheduling endpoints. Conduct an audit of recent booking modifications and deletions to detect potential unauthorized activity.
Risk context
The vulnerability is rated as medium severity with a CVSS v3 score of 3.8, reflecting the requirement for authenticated access and a specific privilege level. The low EPSS score of 0.00132 indicates a currently low probability of active exploitation in the wild, but defenders should still apply standard patch management practices.
Affected products
- Hydra Booking WordPress plugin
Scores
- Severity
- medium
- CVSS v2
- 4.7
- CVSS v3
- 3.8
- CVSS v4
- —
- EPSS
- 0.00132