Description
The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user before modifying or deleting it on two of its booking endpoints, allowing a booking-provider-level user to cancel and permanently delete other providers' bookings on the same site.
Published: 2026-09-19
Score: 3.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Booking Deletion
Action: Patch
AI Analysis

Impact

The Hydra Booking plugin for WordPress fails to check that a booking belongs to the user who requests a modification or deletion. As a result, any booking‑provider level user can cancel or permanently delete bookings created by other providers. This direct manipulation of booking data compromises integrity and availability for competing providers without affecting confidentiality.

Affected Systems

Any WordPress site that uses Hydra Booking—Appointment Scheduling & Booking Calendar before version 1.2.2 is susceptible. The plugin is distributed by an unnamed third‑party vendor, and the exploit applies to all instances where the affected code is loaded, regardless of site configuration.

Risk and Exploitability

The EPSS score of < 1% indicates a very low but non‑zero exploitation probability and the vulnerability is not listed in CISA's KEV catalog. The exploit requires only that the attacker authenticate as a booking‑provider user on the same WordPress installation; no additional network exposure is needed. Because the plugin’s endpoints accept a booking identifier and perform no authorization check, the attack is straightforward to execute once the user roles are established. The severity is low (CVSS 3.8) given the potential for mass booking disruption, and the attack vector is local to the WordPress admin context.

Generated by OpenCVE AI on September 19, 2026 at 23:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Hydra Booking to version 1.2.2 or newer, where the ownership check on booking endpoints has been added.
  • If upgrading immediately is not feasible, restrict booking‑provider users so they can only view, update, or delete bookings they created, for example by adding role‑based filtering or custom code that validates ownership before handling requests.
  • Review all user accounts with booking‑provider privileges to ensure that only trusted personnel have access, and enforce least privilege.

Generated by OpenCVE AI on September 19, 2026 at 23:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions hydra Booking
Vendors & Products Wordpress-extensions
Wordpress-extensions hydra Booking

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L'}


Sat, 19 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Sat, 19 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user before modifying or deleting it on two of its booking endpoints, allowing a booking-provider-level user to cancel and permanently delete other providers' bookings on the same site.
Title Hydra Booking < 1.2.2 - Hydra Host+ Cross-Host Booking Deletion and Modification via IDOR
References

Subscriptions

Wordpress-extensions Hydra Booking
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-19T13:17:26.810Z

Reserved: 2026-09-16T09:54:24.333Z

Link: CVE-2026-92420

cve-icon Vulnrichment

Updated: 2026-09-19T13:10:45.480Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T07:16:33.893

Modified: 2026-09-21T13:34:57.127

Link: CVE-2026-92420

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:49:18Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key