CVE-2025-68055: WordPress Hydra Booking plugin <= 1.1.32 - SQL Injection vulnerability
Published Dec 16, 2025
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking hydra-booking allows SQL Injection.This issue affects Hydra Booking: from n/a through <= 1.1.32.
Affected Software
2 affected components
Themefic Hydra Booking<=1.1.32
wordpress/hydra-booking<=1.1.32
Event History
Dec 16, 2025
CVE Published
via MITRE·08:12 AM
Data Sourced
via MITRE·08:12 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-68055?
CVE-2025-68055 is categorized as a high severity SQL Injection vulnerability.
2
How do I fix CVE-2025-68055?
To fix CVE-2025-68055, upgrade the Themefic Hydra Booking plugin to version 1.1.33 or later.
3
What systems are affected by CVE-2025-68055?
CVE-2025-68055 affects Themefic Hydra Booking versions up to and including 1.1.32.
4
What type of vulnerability is CVE-2025-68055?
CVE-2025-68055 is an SQL Injection vulnerability due to improper neutralization of special elements in SQL commands.
5
Can CVE-2025-68055 lead to data breaches?
Yes, CVE-2025-68055 can lead to unauthorized access to sensitive data due to SQL Injection.