CVE-2026-92421: Hydra Booking 1.1.0 - < 1.2.3 - Hydra Host+ Host Profile Takeover via IDOR
The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the host record being modified belongs to the user making the request, allowing authenticated users holding a Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3-assigned host role to modify other hosts' profile data and reassign ownership of another host's record to themselves.
Affected Software
Event History
Frequently Asked Questions
Which users can exploit this issue?
Exploitation requires authentication and a host role assigned by the Hydra Booking plugin. Users without that plugin-assigned host role are not identified as able to exploit the issue.
What access does a successful attacker gain?
An eligible attacker can modify another host's profile data and change ownership of that host record to themselves. This can result in takeover of another host profile.
Which versions are affected?
Hydra Booking versions before 1.2.3 are affected. Version 1.2.3 is not identified as affected in the provided information.