Back

MEDIUM

Hydra Booking < 1.2.4 - Hydra Host+ Cross-Host Account Modification and Deletion via IDOR

Published Sep 19, 2026

Description

The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level authorisation checks on several of its host-management operations, allowing users who hold its own administrator-assigned custom role to read, modify and permanently delete other hosts' records and the WordPress user accounts linked to them.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Sep 19, 2026
Updated Sep 19, 2026
Reserved Sep 16, 2026
CISA Vulnrichment
Updated Sep 19, 2026
NVD
Status Received
Modified Sep 19, 2026
Red Hat
Severity n/a
Public date n/a