CVE-2026-92420: Hydra Booking < 1.2.2 - Hydra Host+ Cross-Host Booking Deletion and Modification via IDOR
The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user before modifying or deleting it on two of its booking endpoints, allowing a booking-provider-level user to cancel and permanently delete other providers' bookings on the same site.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A booking-provider-level user on the same WordPress site can exploit it. The issue enables one provider to modify, cancel, or permanently delete bookings belonging to other providers.
What access does an attacker need?
The attacker needs booking-provider-level access to the affected Hydra Booking plugin. The available information does not indicate that unauthenticated or ordinary public users can exploit it.
Which plugin versions are affected?
Hydra Booking versions before 1.2.2 are affected. Updating to version 1.2.2 or later addresses the affected version range described here.
How can administrators assess possible impact?
Review booking changes, cancellations, and permanent deletions performed by provider-level accounts, particularly where the acting provider does not own the affected booking. The issue concerns two booking modification or deletion endpoints.