Executive brief
The Hydra Booking plugin for WordPress allows customers to schedule appointments through a public signup form. An attacker can inject malicious JavaScript code through the first name field during registration, which then runs whenever anyone views the booking details. Because the plugin lets new users self-assign a host role via the signup shortcode, this vulnerability is effectively exploitable by anyone without requiring prior authentication.
Technical details
This is a Stored Cross-Site Scripting (XSS) vulnerability in the Hydra Booking WordPress plugin affecting versions up to 1.2.2. The vulnerability exists in the 'first_name' parameter due to insufficient input sanitization and output escaping in the HostsController. An attacker can register via the plugin's public Signup shortcode, self-assign the tfhb_host role, and inject arbitrary JavaScript that persists in the database. The malicious script executes whenever an authorized user accesses a page containing the injected data. While the vulnerability requires the attacker to complete the registration flow, the ability to self-assign the required role makes it exploitable by any unauthenticated visitor.
Affected products
- Hydra Booking Hydra Booking up to and including 1.2.2
Timeline
- 2026-08-15: disclosed