CVE-2026-92425
Received Received - Intake

Hydra Booking Plugin Host Record Manipulation Flaw

Vulnerability report for CVE-2026-92425, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-19

Last updated on: 2026-09-19

Assigner: WPScan

Description

The Hydra Booking β€” Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level authorisation checks on several of its host-management operations, allowing users who hold its own administrator-assigned custom role to read, modify and permanently delete other hosts' records and the WordPress user accounts linked to them.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-19
Last Modified
2026-09-19
Generated
2026-09-20
AI Q&A
2026-09-20
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hydra_booking appointment_scheduling_and_booking_calendar to 1.2.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Hydra Booking WordPress plugin before version 1.2.4. It allows users with a custom administrator role to bypass object-level authorization checks and perform unauthorized actions on other hosts' records and linked WordPress user accounts. This includes reading, modifying, and permanently deleting these records without proper permissions.

Impact Analysis

If you use this plugin, an attacker with a custom administrator role could access, alter, or delete other users' booking data and linked accounts. This could lead to data loss, unauthorized modifications, or disruption of booking services. The impact depends on the plugin's usage and the sensitivity of the data stored.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA by allowing unauthorized access to personal or sensitive data. GDPR requires strict access controls and data protection, while HIPAA mandates safeguards for protected health information. Unauthorized modifications or deletions could violate these regulations.

Mitigation Strategies

Update the Hydra Booking WordPress plugin to version 1.2.4 or later to address the authorization bypass vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92425. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart