medium · CVSS v3 5.5 · EPSS 0.00132
CVE-2026-92425
The Hydra Booking WordPress plugin before version 1.2.4 suffers from an authorization bypass vulnerability in its host-management functions.
Overview
The Hydra Booking WordPress plugin before version 1.2.4 suffers from an authorization bypass vulnerability in its host-management functions. Users assigned a custom plugin role can perform unauthorized read, modify, and delete operations on other hosts' records and linked WordPress accounts. This occurs due to missing object-level authorization checks.
Description
The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level authorisation checks on several of its host-management operations, allowing users who hold its own administrator-assigned custom role to read, modify and permanently delete other hosts' records and the WordPress user accounts linked to them.
Impact
This vulnerability impacts the Confidentiality, Integrity, and Availability of sensitive scheduling data and linked user accounts. Specifically, lower-privileged users with custom plugin roles can compromise other hosts' records and administrative accounts. Organizations utilizing this plugin with multiple custom-role hosts face significant data tampering and account compromise risks.
Remediation
Update the Hydra Booking Appointment Scheduling & Booking Calendar WordPress plugin to version 1.2.4 or later immediately. Review current custom user role assignments and audit plugin privileges to ensure strict adherence to the principle of least privilege.
Risk context
The vulnerability carries a CVSS v3 score of 5.5, designating it as a medium severity risk. The current EPSS score is 0.00132, indicating a relatively low probability of active exploitation in the wild, though remediation should still be prioritized during regular maintenance cycles.
Affected products
- Hydra Booking Appointment Scheduling & Booking Calendar plugin for WordPress < 1.2.4
Scores
- Severity
- medium
- CVSS v2
- 6.8
- CVSS v3
- 5.5
- CVSS v4
- —
- EPSS
- 0.00132