CVE-2025-49378: WordPress Hydra Booking plugin <= 1.1.10 - SQL Injection vulnerability
Published Oct 22, 2025
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking hydra-booking allows SQL Injection.This issue affects Hydra Booking: from n/a through <= 1.1.10.
Affected Software
2 affected components
Themefic Hydra Booking<=1.1.10
WordPress Hydra Booking plugin<=1.1.10
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-49378?
CVE-2025-49378 is considered to have a high severity level due to its potential for SQL Injection exploitation.
2
How do I fix CVE-2025-49378?
To fix CVE-2025-49378, upgrade Themefic Hydra Booking to version 1.1.11 or later.
3
What versions are affected by CVE-2025-49378?
CVE-2025-49378 affects all versions of Themefic Hydra Booking up to and including 1.1.10.
4
What type of vulnerability is CVE-2025-49378?
CVE-2025-49378 is an SQL Injection vulnerability caused by improper neutralization of special elements in SQL commands.
5
Which software products are impacted by CVE-2025-49378?
CVE-2025-49378 impacts the Themefic Hydra Booking and the WordPress Hydra Booking plugin up to version 1.1.10.