Description
The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the host record being modified belongs to the user making the request, allowing authenticated users holding a Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3-assigned host role to modify other hosts' profile data and reassign ownership of another host's record to themselves.
Published: 2026-09-19
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation (Host Profile Takeover)
Action: Update Plugin
AI Analysis

Impact

The vulnerability allows an authenticated user with a host role in the Hydra Booking WordPress plugin to modify any host profile within the system. By providing the identifier of another host, the attacker can change that host's data and even transfer ownership of the host record to their own account. This results in unauthorized changes to personal information, potential misuse of host privileges, and compromise of the integrity of the booking system.

Affected Systems

WordPress sites using the Hydra Booking – Appointment Scheduling & Booking Calendar plugin with a version earlier than 1.2.3 are impacted. Any user assigned a host role on such installations can exploit the flaw.

Risk and Exploitability

The exploit requires only an authenticated host role account, so any legitimate user with that role can run the attack. The CVSS score is 4.7, and the EPSS score is less than 1%, but the vulnerability is not listed in the CISA KEV catalog. Because the flaw is an IDOR, the likelihood of exploitation depends on the presence of exposed host identifiers in the application’s URLs or APIs. The risk level is moderate to high for sites whose host records contain sensitive data or where host management is critical.

Generated by OpenCVE AI on September 19, 2026 at 23:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest version of the Hydra Booking plugin (1.2.3 or later) to remove the IDOR flaw.
  • If an immediate update is not possible, remove the host role from all users or replace it with a more restrictive custom role that does not allow profile editing.
  • Audit all host profiles for unauthorized changes and document any misuse before applying remediation.

Generated by OpenCVE AI on September 19, 2026 at 23:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions hydra Booking
Vendors & Products Wordpress-extensions
Wordpress-extensions hydra Booking

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}


Sat, 19 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Sat, 19 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the host record being modified belongs to the user making the request, allowing authenticated users holding a Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3-assigned host role to modify other hosts' profile data and reassign ownership of another host's record to themselves.
Title Hydra Booking 1.1.0 - < 1.2.3 - Hydra Host+ Host Profile Takeover via IDOR
References

Subscriptions

Wordpress-extensions Hydra Booking
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-19T13:17:11.888Z

Reserved: 2026-09-16T09:54:43.365Z

Link: CVE-2026-92421

cve-icon Vulnrichment

Updated: 2026-09-19T13:10:35.915Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T07:16:34.000

Modified: 2026-09-21T13:34:57.127

Link: CVE-2026-92421

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:49:16Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key