medium · CVSS v3 4.7 · EPSS 0.00132
CVE-2026-92421
An Insecure Direct Object Reference vulnerability exists in the Hydra Booking Appointment Scheduling & Booking Calendar WordPress plugin bef
Overview
An Insecure Direct Object Reference vulnerability exists in the Hydra Booking Appointment Scheduling & Booking Calendar WordPress plugin before version 1.2.3. The flaw occurs because the plugin fails to verify whether the host record being modified belongs to the authenticated user making the request. Consequently, low-privileged host users can alter other hosts' profile data and reassign ownership of records.
Description
The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the host record being modified belongs to the user making the request, allowing authenticated users holding a Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3-assigned host role to modify other hosts' profile data and reassign ownership of another host's record to themselves.
Impact
This vulnerability impacts the Confidentiality and Integrity of scheduling data stored within the WordPress plugin. Authenticated users with the host role can unauthorizedly access, modify, and hijack profile records belonging to other hosts. It does not lead to direct remote code execution or complete system compromise, but it undermines data integrity and user separation within the application.
Remediation
Update the Hydra Booking Appointment Scheduling & Booking Calendar WordPress plugin to version 1.2.3 or later immediately. Ensure proper authorization checks are enforced for all host record modification functions. Conduct a security review of user roles and recent booking record modifications to detect potential unauthorized changes.
Risk context
The vulnerability is rated as medium severity with a CVSS base score of 4.7. The EPSS score is 0.00132, indicating a very low probability of active exploitation in the wild at this time. However, remediation should be prioritized as part of routine plugin maintenance to prevent unauthorized data tampering.
Affected products
- Hydra Booking WordPress Plugin
Scores
- Severity
- medium
- CVSS v2
- 5.8
- CVSS v3
- 4.7
- CVSS v4
- —
- EPSS
- 0.00132