Description
Incorrect Privilege Assignment vulnerability in Themefic Hydra Booking hydra-booking allows Privilege Escalation.This issue affects Hydra Booking: from n/a through <= 1.1.32.
Published: 2026-01-22
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Update Plugin
AI Analysis

Impact

The vulnerability is an incorrect privilege assignment that allows an attacker to elevate their privileges within the WordPress installation when Hydra Booking plugin is at or below version 1.1.32. The flaw permits an authenticated user to gain higher permissions than intended, potentially enabling the creation, modification, or deletion of booking data and related administrative functions. This impact compromises the confidentiality, integrity, and availability of data managed by the plugin and can facilitate further misuse of the WordPress site.

Affected Systems

Vendors and products impacted are Themefic Hydra Booking for WordPress. All installations using any release from the first public build up to and including version 1.1.32 are susceptible. No specific minor or patch versions beyond 1.1.32 provide a fix; users must upgrade to 1.1.33 or later to remediate the flaw.

Risk and Exploitability

The CVSS score of 7.3 indicates moderate to high severity for the exposure. The EPSS score of <1% suggests that, as of the current data, the exploitation probability is low but still present. The vulnerability is not listed in CISA’s KEV catalog, so no active widespread exploitation has been observed. The likely attack vector is through the web application: an attacker who can authenticate to the WordPress site with a role that includes access to Hydra Booking settings could exploit the privilege assignment flaw by navigating to plugin pages or submitting crafted requests. Successful exploitation requires valid credentials but does not necessitate administrative rights beforehand, making it a serious risk for sites with a large user base.

Generated by OpenCVE AI on April 27, 2026 at 21:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Hydra Booking to version 1.1.33 or higher, ensuring the patch that fixes the privilege assignment issue is applied
  • If an upgrade is not immediately possible, restrict the plugin’s administrative pages to administrators only by applying role‑based access controls in WordPress
  • Validate that all user roles interacting with Hydra Booking are operating under the minimum necessary privileges and remove any custom roles that grant broader permissions than required

Generated by OpenCVE AI on April 27, 2026 at 21:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 28 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Themefic
Themefic hydra Booking
Wordpress
Wordpress wordpress
Vendors & Products Themefic
Themefic hydra Booking
Wordpress
Wordpress wordpress

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Incorrect Privilege Assignment vulnerability in Themefic Hydra Booking hydra-booking allows Privilege Escalation.This issue affects Hydra Booking: from n/a through <= 1.1.32.
Title WordPress Hydra Booking plugin <= 1.1.32 - Privilege Escalation vulnerability
Weaknesses CWE-266
References

Subscriptions

Themefic Hydra Booking
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T19:55:40.115Z

Reserved: 2025-12-15T10:00:59.034Z

Link: CVE-2025-68027

cve-icon Vulnrichment

Updated: 2026-01-28T20:21:19.962Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:16:08.600

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-68027

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-27T21:30:13Z

Weaknesses