Description
Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versions.
Published: 2026-08-13
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

UnAuthenticated Broken Access Control exists in WordPress Hydra Booking plugin versions 1.2.2 and earlier. The flaw permits a remote attacker who does not hold user credentials to access administrative functions or sensitive booking data. This weakness, identified as CWE‑862, allows unauthenticated manipulation of booking records or exposure of private information.

Affected Systems

The issue affects sites running the Hydra Booking plugin from themefic, specifically versions 1.2.2 and earlier. WordPress installations that have not upgraded beyond these releases are vulnerable.

Risk and Exploitability

With a CVSS score of 7.3, the vulnerability carries high severity. No EPSS score is reported and it is not listed in CISA KEV, but because authentication is not required, exploitation merely requires sending crafted HTTP requests to the plugin’s endpoints, making the barrier low for attackers who discover it.

Generated by OpenCVE AI on August 13, 2026 at 15:57 UTC.

Remediation

Vendor Solution

Update the WordPress Hydra Booking plugin to the latest available version (at least 1.2.3).


OpenCVE Recommended Actions

  • Upgrade the Hydra Booking plugin to the latest version (at least 1.2.3) as provided by the vendor.
  • Configure role‑based access controls or web‑server rules to restrict administrative URLs of the plugin to authorized users only.
  • Monitor HTTP logs for unexpected or repeated requests targeting the plugin’s admin pages and generate alerts for suspicious activity.

Generated by OpenCVE AI on August 13, 2026 at 15:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Themefic
Themefic hydra Booking
Wordpress
Wordpress wordpress
Vendors & Products Themefic
Themefic hydra Booking
Wordpress
Wordpress wordpress

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versions.
Title WordPress Hydra Booking plugin <= 1.2.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Themefic Hydra Booking
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:25:36.506Z

Reserved: 2026-02-25T12:14:47.651Z

Link: CVE-2026-28188

cve-icon Vulnrichment

Updated: 2026-08-13T15:25:32.010Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T14:17:00.870

Modified: 2026-08-14T19:09:20.713

Link: CVE-2026-28188

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:45:03Z

Weaknesses