Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesHydra Booking

Hydra Booking vulnerabilities

Hydra Booking has 8 known vulnerabilities in this database. The most recent published record is dated 19 Sep 2026.

Known vulnerabilities
8
Active installs
2,000+
Latest version
1.2.6
Last updated
16 Sep 2026
Most recent
19 Sep 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Broken access control
CVE-2026-92421
Medium 4.7Before 1.2.3Fixed in 1.2.319 Sep 2026
Broken access control
CVE-2026-92425
Medium 5.5Before 1.2.4Fixed in 1.2.419 Sep 2026
Broken access control
CVE-2026-92420
Low 3.8Before 1.2.2Fixed in 1.2.219 Sep 2026
Cross-site scripting (XSS)
CVE-2026-15948
Medium 6.4Up to 1.2.2Fixed in a later version (latest 1.2.6)15 Aug 2026
Broken access control
CVE-2026-12433
Medium 4.3Up to 1.2.1Fixed in a later version (latest 1.2.6)9 Jul 2026
Broken access control
CVE-2025-12787
Medium 5.3Up to 1.1.27Fixed in a later version (latest 1.2.6)11 Nov 2025
Security weakness
CVE-2025-12788
Medium 5.3Up to 1.1.27Fixed in a later version (latest 1.2.6)11 Nov 2025
Privilege escalation
CVE-2025-7689
High 8.8Not yet publishedCheck for an update29 Jul 2025
Read the published descriptions
CVE-2026-92421, 19 Sep 2026
The Hydra Booking - Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the host record being modified belongs to the user making the request, allowing authenticated users holding a Hydra Booking - Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3-assigned host role to modify other hosts' profile data and reassign ownership of another host's record to themselves. CVE record
CVE-2026-92425, 19 Sep 2026
The Hydra Booking - Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level authorisation checks on several of its host-management operations, allowing users who hold its own administrator-assigned custom role to read, modify and permanently delete other hosts' records and the WordPress user accounts linked to them. CVE record
CVE-2026-92420, 19 Sep 2026
The Hydra Booking - Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user before modifying or deleting it on two of its booking endpoints, allowing a booking-provider-level user to cancel and permanently delete other providers' bookings on the same site. CVE record
CVE-2026-15948, 15 Aug 2026
The Hydra Booking - Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with host-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The tfhb_host role required to exploit this vulnerability can be self-assigned by any visitor via the plugin's public Signup shortcode, making this effectively exploitable by unauthenticated users who complete the registration flow. CVE record
CVE-2026-12433, 9 Jul 2026
The Hydra Booking - Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.2.1 via the /wp-json/hydra-booking/v1/booking/details/{id} REST endpoint. This is due to the getBookingDetails() callback only enforcing the tfhb_manage_options capability via tfhb_manage_options_permission(), without verifying that the requested booking belongs to the currently authenticated host (the lookup in getBookingDetailsData() filters solely on the booking id supplied in the URL). This makes it possible for authenticated attackers, with Hydra Host-level access and above (a role created by the plugin which grants tfhb_manage_options), to view sensitive booking records belonging to other hosts, including attendee names, emails, phone numbers, addresses, meeting details, payment method and status, transaction history, and internal notes by iterating booking IDs. CVE record
CVE-2025-12787, 11 Nov 2025
The Hydra Booking - Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to unauthorized booking cancellation in all versions up to, and including, 1.1.27. This is due to the plugin's "tfhb_meeting_form_submit_callback" function using insufficiently random values to generate booking cancellation tokens, combined with a globally shared nonce. This makes it possible for unauthenticated attackers to cancel arbitrary bookings via brute force attacks against the tfhb_meeting_form_cencel AJAX endpoint. CVE record
CVE-2025-12788, 11 Nov 2025
The Hydra Booking - Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to missing payment verification to unauthenticated payment bypass in all versions up to, and including, 1.1.27. This is due to the plugin accepting client-controlled payment confirmation data in the tfhb_meeting_paypal_payment_confirmation_callback function without server-side verification with PayPal's API. This makes it possible for unauthenticated attackers to bypass payment requirements and confirm bookings as paid without any actual payment transaction occurring. CVE record
CVE-2025-7689, 29 Jul 2025
The Hydra Booking plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the tfhb_reset_password_callback() function in versions 1.1.0 to 1.1.18. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset the password of an Administrator user, achieving full privilege escalation. CVE record

What to do if you run Hydra Booking

If you run Hydra Booking, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Hydra Booking vulnerabilities

Free. We email you when a new vulnerability is published for Hydra Booking, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support