CVE-2025-49323: WordPress Hydra Booking plugin <= 1.1.10 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking allows SQL Injection. This issue affects Hydra Booking: from n/a through 1.1.10.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking hydra-booking allows SQL Injection.This issue affects Hydra Booking: from n/a through <= 1.1.10.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49323?
The severity of CVE-2025-49323 is considered high due to its potential for SQL Injection exploitation.
How do I fix CVE-2025-49323?
To fix CVE-2025-49323, update Themefic Hydra Booking to version 1.1.11 or later.
What versions are affected by CVE-2025-49323?
CVE-2025-49323 affects all versions of Themefic Hydra Booking up to and including 1.1.10.
What type of vulnerability is CVE-2025-49323?
CVE-2025-49323 is an SQL Injection vulnerability stemming from improper neutralization of special elements in SQL commands.
What software does CVE-2025-49323 impact?
CVE-2025-49323 impacts Themefic Hydra Booking and WordPress Hydra Booking up to version 1.1.10.