CVE-2026-92420
Received Received - Intake

Hydra Booking Plugin Booking Manipulation Vulnerability

Vulnerability report for CVE-2026-92420, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-19

Last updated on: 2026-09-19

Assigner: WPScan

Description

The Hydra Booking β€” Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user before modifying or deleting it on two of its booking endpoints, allowing a booking-provider-level user to cancel and permanently delete other providers' bookings on the same site.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-19
Last Modified
2026-09-19
Generated
2026-09-20
AI Q&A
2026-09-20
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hydra_booking appointment_scheduling_and_booking_calendar to 1.2.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Hydra Booking WordPress plugin before version 1.2.2. It allows a user with booking-provider-level access to modify or delete bookings without verifying ownership. Specifically, it affects two booking endpoints where the plugin fails to check if a booking belongs to the requesting user before performing actions like cancellation or permanent deletion.

Detection Guidance

To detect this vulnerability, inspect WordPress sites using the Hydra Booking plugin version before 1.2.2. Check for unauthorized modifications or deletions of bookings by non-owner users. Review server logs for suspicious activity on booking endpoints.

Impact Analysis

If you are a booking provider using this plugin, an attacker with provider-level access could cancel or delete your bookings without your consent. This could disrupt your services, lead to lost appointments, and damage your reputation. Users relying on these bookings may also face inconvenience or service disruptions.

Mitigation Strategies

Immediately update the Hydra Booking plugin to version 1.2.2 or later. Remove or restrict access for booking-provider-level users until the update is applied. Monitor booking activities for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92420. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart