CVE-2026-42675: WordPress Hydra Booking plugin <= 1.1.41 - Broken Access Control vulnerability
Missing Authorization vulnerability in Themefic Hydra Booking allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Hydra Booking: from n/a through 1.1.41.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/Hydra Booking Pluginto a version that resolves this vulnerability.Fixed in 1.1.42
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42675?
CVE-2026-42675 has a severity rating of high with a score of 7.3.
How do I fix CVE-2026-42675?
To fix CVE-2026-42675, update the WordPress Hydra Booking Plugin to version 1.1.42 or later.
What type of vulnerability is CVE-2026-42675?
CVE-2026-42675 is a Broken Access Control vulnerability.
Which versions are affected by CVE-2026-42675?
CVE-2026-42675 affects all versions of the Themefic Hydra Booking plugin up to and including 1.1.41.
What consequences can arise from CVE-2026-42675?
Exploiting CVE-2026-42675 could allow unauthorized access due to incorrectly configured access control security levels.