Impact
The vulnerability allows an authenticated user with a host role in the Hydra Booking WordPress plugin to modify any host profile within the system. By providing the identifier of another host, the attacker can change that host's data and even transfer ownership of the host record to their own account. This results in unauthorized changes to personal information, potential misuse of host privileges, and compromise of the integrity of the booking system.
Affected Systems
WordPress sites using the Hydra Booking – Appointment Scheduling & Booking Calendar plugin with a version earlier than 1.2.3 are impacted. Any user assigned a host role on such installations can exploit the flaw.
Risk and Exploitability
The exploit requires only an authenticated host role account, so any legitimate user with that role can run the attack. The CVSS score is 4.7, and the EPSS score is less than 1%, but the vulnerability is not listed in the CISA KEV catalog. Because the flaw is an IDOR, the likelihood of exploitation depends on the presence of exposed host identifiers in the application’s URLs or APIs. The risk level is moderate to high for sites whose host records contain sensitive data or where host management is critical.
OpenCVE Enrichment