CVE-2026-92425: Hydra Booking < 1.2.4 - Hydra Host+ Cross-Host Account Modification and Deletion via IDOR
The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level authorisation checks on several of its host-management operations, allowing users who hold its own administrator-assigned custom role to read, modify and permanently delete other hosts' records and the WordPress user accounts linked to them.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user with the plugin's administrator-assigned custom role can exploit the affected host-management operations. The issue is not described as exploitable by unauthenticated visitors.
What access does a successful attacker gain over other hosts?
They can read, modify, and permanently delete other hosts' records. They can also permanently delete the WordPress user accounts linked to those hosts.
Which installations are affected?
Hydra Booking — Appointment Scheduling & Booking Calendar versions before 1.2.4 are affected. The provided information does not state whether the vulnerable custom role is assigned by default.