Impact
UnAuthenticated Broken Access Control exists in WordPress Hydra Booking plugin versions 1.2.2 and earlier. The flaw permits a remote attacker who does not hold user credentials to access administrative functions or sensitive booking data. This weakness, identified as CWE‑862, allows unauthenticated manipulation of booking records or exposure of private information.
Affected Systems
The issue affects sites running the Hydra Booking plugin from themefic, specifically versions 1.2.2 and earlier. WordPress installations that have not upgraded beyond these releases are vulnerable.
Risk and Exploitability
With a CVSS score of 7.3, the vulnerability carries high severity. No EPSS score is reported and it is not listed in CISA KEV, but because authentication is not required, exploitation merely requires sending crafted HTTP requests to the plugin’s endpoints, making the barrier low for attackers who discover it.
OpenCVE Enrichment