Impact
The Hydra Booking plugin for WordPress fails to check that a booking belongs to the user who requests a modification or deletion. As a result, any booking‑provider level user can cancel or permanently delete bookings created by other providers. This direct manipulation of booking data compromises integrity and availability for competing providers without affecting confidentiality.
Affected Systems
Any WordPress site that uses Hydra Booking—Appointment Scheduling & Booking Calendar before version 1.2.2 is susceptible. The plugin is distributed by an unnamed third‑party vendor, and the exploit applies to all instances where the affected code is loaded, regardless of site configuration.
Risk and Exploitability
The EPSS score of < 1% indicates a very low but non‑zero exploitation probability and the vulnerability is not listed in CISA's KEV catalog. The exploit requires only that the attacker authenticate as a booking‑provider user on the same WordPress installation; no additional network exposure is needed. Because the plugin’s endpoints accept a booking identifier and perform no authorization check, the attack is straightforward to execute once the user roles are established. The severity is low (CVSS 3.8) given the potential for mass booking disruption, and the attack vector is local to the WordPress admin context.
OpenCVE Enrichment