Junglewise Threat Intelligence

CVE-2026-39541: Themefic Hydra Booking Stored XSS

CVE-2026-39541 · Severity: medium · CVSS 5.9 · Published 2026-04-08

Technologies: Themefic Hydra Booking. Vendors: Themefic.

Executive brief

Themefic Hydra Booking, a WordPress plugin used for managing reservations and bookings, contains a security flaw that allows for stored cross-site scripting. An attacker with high-level administrative privileges can inject malicious scripts into the website's pages. If a site visitor or another administrator views the affected page, these scripts could be used to redirect users to malicious sites, display unauthorized advertisements, or steal session information.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Themefic Hydra Booking plugin for WordPress (versions <= 1.1.38) due to improper neutralization of user-supplied input during web page generation. The vulnerability requires high-level privileges (Hydra Host role) to inject malicious payloads into the database. Successful exploitation occurs when a victim, such as a site administrator or guest, interacts with the affected page, causing the script to execute in their browser context. This can lead to unauthorized actions, data theft, or site defacement. The issue is resolved in version 1.1.39.

Affected products

  • Themefic Hydra Booking <= 1.1.38

Timeline

  • 2026-01-16: disclosed: Reported by benzdeus via Patchstack
  • 2026-02-15: advisory: Initial advisory published by Patchstack
  • 2026-04-08: advisory: NVD publication date
  • 2026-02-15: patched: Patch released in version 1.1.39

References

Related threats