Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Booking hydra-booking allows Stored XSS.This issue affects Hydra Booking: from n/a through <= 1.1.44.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WordPress Hydra Booking plugin suffers from an improper neutralization of user input during page generation, which enables a stored cross‑site scripting flaw. A malicious script stored in a plugin field can execute in any visitor’s browser when the affected page is rendered. This can allow attackers to deface content, phish users, or steal credentials; the exact damage depends on the payload and the page interaction, and is therefore inferred from common XSS consequences.

Affected Systems

All installations of the Themefic Hydra Booking plugin version 1.1.44 or earlier on WordPress sites are affected. The vulnerability applies to any WordPress instance that has the plugin active, regardless of the number of users or specific configuration.

Risk and Exploitability

The CVSS score of 7.1 indicates moderate‑to‑high severity, while the EPSS score of less than 1% suggests that exploitation attempts are currently rare. Based on the description, the likely attack vector is the web interface of the plugin that accepts user input; an attacker would embed a malicious payload into a stored field, which is then rendered to all users who view the affected page. The vulnerability is not listed in the CISA KEV catalog, so no large‑scale, actively exploited campaigns have been reported.

Generated by OpenCVE AI on July 31, 2026 at 12:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Hydra Booking plugin to a version newer than 1.1.44 to eliminate the stored XSS flaw.
  • If an upgrade cannot be performed immediately, limit the use of plugin booking‑form fields to trusted users only and enforce strong authentication on pages that accept input.
  • Remove or disable the Hydra Booking plugin entirely if the booking functionality is not required.

Generated by OpenCVE AI on July 31, 2026 at 12:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Themefic
Themefic hydra Booking
Wordpress
Wordpress wordpress
Vendors & Products Themefic
Themefic hydra Booking
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Booking hydra-booking allows Stored XSS.This issue affects Hydra Booking: from n/a through <= 1.1.44.
Title WordPress Hydra Booking plugin <= 1.1.44 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Themefic Hydra Booking
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:48:59.240Z

Reserved: 2026-06-24T12:46:01.632Z

Link: CVE-2026-57388

cve-icon Vulnrichment

Updated: 2026-07-13T13:48:56.157Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')