rootpwn

medium · CVSS v3 5.5 · EPSS 0.00132

CVE-2026-92425

The Hydra Booking WordPress plugin before version 1.2.4 suffers from an authorization bypass vulnerability in its host-management functions.

Overview

The Hydra Booking WordPress plugin before version 1.2.4 suffers from an authorization bypass vulnerability in its host-management functions. Users assigned a custom plugin role can perform unauthorized read, modify, and delete operations on other hosts' records and linked WordPress accounts. This occurs due to missing object-level authorization checks.

Description

The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level authorisation checks on several of its host-management operations, allowing users who hold its own administrator-assigned custom role to read, modify and permanently delete other hosts' records and the WordPress user accounts linked to them.

Impact

This vulnerability impacts the Confidentiality, Integrity, and Availability of sensitive scheduling data and linked user accounts. Specifically, lower-privileged users with custom plugin roles can compromise other hosts' records and administrative accounts. Organizations utilizing this plugin with multiple custom-role hosts face significant data tampering and account compromise risks.

Remediation

Update the Hydra Booking Appointment Scheduling & Booking Calendar WordPress plugin to version 1.2.4 or later immediately. Review current custom user role assignments and audit plugin privileges to ensure strict adherence to the principle of least privilege.

Risk context

The vulnerability carries a CVSS v3 score of 5.5, designating it as a medium severity risk. The current EPSS score is 0.00132, indicating a relatively low probability of active exploitation in the wild, though remediation should still be prioritized during regular maintenance cycles.

Affected products

  • Hydra Booking Appointment Scheduling & Booking Calendar plugin for WordPress < 1.2.4

Scores

Severity
medium
CVSS v2
6.8
CVSS v3
5.5
CVSS v4
EPSS
0.00132

CVE-2026-92425 WordPress Plugin Authorization Bypass IDOR Medium Severity Defensive Analysis

← All CVEs