CVE-2026-28188: WordPress Hydra Booking plugin <= 1.2.2 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Hydra Booking pluginto a version that resolves this vulnerability.Fixed in 1.2.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28188?
CVE-2026-28188 has a severity score of 7.3, indicating a high level of risk.
What is CVE-2026-28188?
CVE-2026-28188 is an unauthenticated Broken Access Control vulnerability in the Hydra Booking plugin for WordPress, affecting versions up to 1.2.2.
How do I fix CVE-2026-28188?
To fix CVE-2026-28188, update the Hydra Booking plugin to the latest version that addresses this vulnerability.
Who is affected by CVE-2026-28188?
Users of WordPress who have the Hydra Booking plugin version 1.2.2 or earlier are affected by CVE-2026-28188.
What impact does CVE-2026-28188 have?
CVE-2026-28188 allows unauthorized users to gain access to restricted functionalities, potentially leading to data exposure or modification.