Impact
The Hydra Booking plugin for WordPress allows an administrator‑assigned custom role to view, change, or delete host records and the WordPress user accounts linked to those hosts because it fails to verify object‑level permissions in several host‑management functions. This missing authorization check lets a privileged user alter ownership data, remove scheduled hosts, and permanently delete associated user accounts, effectively granting unauthorized control and data loss.
Affected Systems
The vulnerability affects the Hydra Booking – Appointment Scheduling & Booking Calendar WordPress plugin versions prior to 1.2.4. All installations using the default host‑management features and the custom administrator role defined in earlier releases are impacted.
Risk and Exploitability
Exploit requires possession of the plugin’s custom administrator role or any role with equivalent host‑management privileges. No public exploit or KEV listing is presently known, and the EPSS score is < 1%, but the CVSS score of 5.5 indicates medium severity. The missing authorization check means any user granted that role could perform destructive operations without additional authentication. Based on the description, it is inferred that if the custom administrator role is widely assigned, the risk could be significant, whereas tighter control of that role reduces the overall threat level. The vulnerability does not permit external remote code execution.
OpenCVE Enrichment