Impact
WordPress Hydra Booking plugin suffers from an improper neutralization of user input during page generation, which enables a stored cross‑site scripting flaw. A malicious script stored in a plugin field can execute in any visitor’s browser when the affected page is rendered. This can allow attackers to deface content, phish users, or steal credentials; the exact damage depends on the payload and the page interaction, and is therefore inferred from common XSS consequences.
Affected Systems
All installations of the Themefic Hydra Booking plugin version 1.1.44 or earlier on WordPress sites are affected. The vulnerability applies to any WordPress instance that has the plugin active, regardless of the number of users or specific configuration.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate‑to‑high severity, while the EPSS score of less than 1% suggests that exploitation attempts are currently rare. Based on the description, the likely attack vector is the web interface of the plugin that accepts user input; an attacker would embed a malicious payload into a stored field, which is then rendered to all users who view the affected page. The vulnerability is not listed in the CISA KEV catalog, so no large‑scale, actively exploited campaigns have been reported.
OpenCVE Enrichment