Impact
The Hydra Booking plugin for WordPress has a classic sql injection flaw where user input is incorporated directly into an SQL command without proper escaping. This flaw allows an attacker to manipulate queries, potentially reading, altering, or deleting data in the site’s database, and could also be leveraged for broader compromise depending on database permissions.
Affected Systems
Affected systems are installations of the Themefic Hydra Booking plugin up to and including version 1.1.10. The vulnerability is present in all versions from the earliest releases through 1.1.10 and does not affect later releases. Any WordPress site that has not upgraded beyond this version is at risk.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. The EPSS score is reported as less than 1%, implying a very low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via the public web interface that processes booking requests. Attackers would need write or read access to the underlying database to fully exploit the flaw.
OpenCVE Enrichment
EUVD